PUP.MSIL.HackAgent.X

Analysis Report

General information

Family Name: PUP.MSIL.HackAgent.X
Signature status: No Signature

Known Samples

MD5: dcbbe7c8ae90b44ca01256b6cc85d294
SHA1: 0a0e3a20fb91d63973b1fd92671dfb83424a11d2
SHA256: 138D24E8FDA0309E506BA54A542747C457B62A1A7367E395DCD2A872E8A65663
File Size: 785.92 KB, 785920 bytes
MD5: fc49c060fcfeb4cf5e3846df081875fb
SHA1: 029a50ad4b6b8d2afb53959451894b279b6b88bd
SHA256: CF44D1E4F2DB7FB7580266DFDA3ADD30CA7A197AA18DA809E55BD63334C382FC
File Size: 673.57 KB, 673574 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Comments Camtasia 8.XX Activator
Company Name Slogutis@DevPoint
File Description Camtasia 8.XX Activator
File Version
  • 1.00
  • 1.0.0.0
Internal Name
  • Camtasia 8.XX Activator.exe
  • TJprojMain
Legal Copyright Slogutis©2015
Original Filename
  • Camtasia 8.XX Activator.exe
  • TJprojMain.exe
Product Name
  • Camtasia 8.XX Activator
  • Project1
Product Version
  • 1.00
  • 1.0.0.0

File Traits

  • .NET
  • .sdata
  • HighEntropy
  • NewLateBinding
  • x86

Block Information

Similar Families

  • Autoclicker.DA
  • Autoclicker.HH
  • MSIL.HackAgent.X
  • MSIL.HackAgent.XC
  • MSIL.OpenSUpdater.BP
Show More
  • MSIL.Tiny.CU

Files Modified

File Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve.log1 Read Data,Write Data
c:\windows\appcompat\programs\amcache.hve.log2 Read Data,Write Data

Windows API Usage

Category API
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider
Process Manipulation Evasion
  • ReadProcessMemory
Other Suspicious
  • SetWindowsHookEx

Shell Command Execution

C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 940

Trending

Most Viewed

Loading...