PUP.MSIL.DotNetGuard.X

Analysis Report

General information

Family Name: PUP.MSIL.DotNetGuard.X
Signature status: No Signature

Known Samples

MD5: 94b0dbc92bc0ad7a689cd7569ef8e329
SHA1: d51184c6e949457b32a549fe3878ccb2928d23e6
SHA256: BE5451C28FCF2EADB51258D5BB274DF8FBF411972A2C669833A53F128D6382BD
File Size: 8.20 MB, 8197120 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.1.0.0
Company Name Radeon.Core.BasePatch
File Description Radeon.Core.BasePatch
File Version 1.1.0.0
Internal Name Radeon.Core.BasePatch.dll
Original Filename Radeon.Core.BasePatch.dll
Product Name Awesome Base Patch for Radeon
Product Version 1.1.0+3f45d02dc602c2a07989c93b31e6f25b5b0f0a7d

File Traits

  • .NET
  • dll
  • x86

Block Information

Total Blocks: 473
Potentially Malicious Blocks: 415
Whitelisted Blocks: 58
Unknown Blocks: 0

Visual Map

0 0 0 0 x x x 0 x 0 0 x 0 x x x x x x x 0 0 0 0 0 x x 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 x x 0 0 0 0 x x 0 0 x x x x x x x x x x 0 0 0 0 0 0 x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x 0 0 0 0 x x x x x 0 x 0 x x 0 x x x x x x x x 0 x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x x x x x x x x x 0 0 x x x x x x x x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.DotNetGuard.X

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\d51184c6e949457b32a549fe3878ccb2928d23e6_0008197120.,LiQMAxHB

Trending

Most Viewed

Loading...