PUP.Nuitika.D
Table of Contents
Analysis Report
General information
| Family Name: | PUP.Nuitika.D |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
0df18af825ecf2b579983d5ba7c45c67
SHA1:
e031c10fb5becab49120ff8e1b2f370837fcf1b6
File Size:
7.75 MB, 7754240 bytes
|
|
MD5:
26cf25a229fac5fb4b3f0befe517fdf8
SHA1:
a2b43b7e635d14486c101417454e363ab906fb1a
SHA256:
3C642646A92222EB0D7F17E57BAA5B5A2D84122E8ED3CCE297D4C3564EA8C4EE
File Size:
8.96 MB, 8961024 bytes
|
|
MD5:
cc5289f7c76bcd81f8e5f7e9cd603627
SHA1:
9093f64d66f6a1c3cbe78eddd08e4a1c36b4591d
SHA256:
FD7D2CC9EC9166CAD67A247746AF681D76F14EC34FBCBDD9BEC764395A47B5AA
File Size:
8.93 MB, 8933376 bytes
|
|
MD5:
1efd7a678b82bc3a83b95b4cd1ecb569
SHA1:
d8a944e1e8c2304497f0cd6082900af91a1375f8
SHA256:
CE0CDD233269417D4DB0CA300F0B018B31485C1522DDCCA5563CDDABA75913ED
File Size:
9.63 MB, 9625600 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have security information
- File has TLS information
- File is 64-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
Show More
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Company Name | Raven Development Team |
| File Description |
|
| File Version |
|
| Internal Name |
|
| Legal Copyright | Copyright (c) 2025 Raven Development Team |
| Original Filename |
|
| Product Name |
|
| Product Version |
|
File Traits
- No Version Info
- x64
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 37,897 |
|---|---|
| Potentially Malicious Blocks: | 6,925 |
| Whitelisted Blocks: | 29,244 |
| Unknown Blocks: | 1,728 |
Visual Map
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
x
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
x
0
0
x
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
x
0
0
0
0
0
x
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
x
x
0
x
x
0
0
0
0
0
?
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
x
0
0
x
0
0
0
0
0
x
0
x
0
0
x
0
0
0
0
0
x
0
x
0
0
x
0
0
0
0
0
x
0
x
0
0
?
?
0
0
x
0
0
0
0
0
0
0
0
0
0
?
0
0
?
0
0
x
0
0
0
?
0
0
0
0
?
0
0
0
0
0
x
0
x
0
0
x
0
0
0
0
0
x
0
0
0
?
0
0
0
0
0
?
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
x
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
x
0
0
0
0
0
x
0
x
0
0
x
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
x
0
?
?
?
0
x
0
0
0
0
0
0
?
0
x
x
0
?
0
?
0
x
?
?
0
0
0
x
?
0
0
0
0
0
0
0
?
0
0
?
0
0
x
x
0
0
x
0
0
0
0
0
x
?
0
0
0
0
0
0
0
x
0
0
0
?
0
0
0
0
x
0
0
?
x
0
0
0
?
0
0
x
?
0
0
0
0
0
0
0
0
0
0
0
0
?
?
x
0
0
0
?
0
?
0
0
?
?
0
0
?
0
0
0
0
0
?
0
0
0
0
0
0
0
x
0
0
0
0
x
?
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
x
0
0
x
0
0
0
0
0
x
x
x
0
0
0
x
x
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
x
0
0
0
x
0
x
x
0
0
0
0
0
x
0
0
x
x
x
0
x
0
0
x
0
x
0
x
0
x
0
0
0
0
0
0
0
x
0
0
0
0
x
0
x
0
0
x
0
x
x
0
0
x
0
0
0
0
0
0
x
0
x
0
0
0
0
0
x
0
0
0
0
0
0
0
x
0
0
0
0
x
0
0
0
x
0
0
x
0
0
x
0
0
x
x
0
0
0
x
0
x
x
0
0
0
x
0
x
x
0
x
x
x
0
0
x
0
x
0
0
0
0
0
0
x
0
0
x
0
0
0
0
0
0
?
x
0
?
0
?
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
x
0
0
0
0
0
?
x
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
x
0
0
0
0
0
0
0
0
x
0
0
x
0
0
0
x
0
0
0
0
0
x
0
x
x
0
0
0
x
0
0
0
0
0
0
0
0
x
x
0
x
x
0
0
0
0
0
x
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
?
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
?
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
?
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
x
0
x
0
0
x
0
0
x
0
0
0
0
0
0
?
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
x
0
0
x
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
x
0
x
0
x
0
x
0
x
0
x
0
x
0
x
0
x
0
x
0
x
0
x
0
x
0
x
0
x
0
x
0
x
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
?
x
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
x
0
0
x
0
0
x
0
0
0
0
0
x
0
x
0
0
x
0
0
0
0
0
x
0
x
0
0
x
0
0
0
0
0
x
0
x
0
0
x
0
0
0
0
0
x
0
0
x
0
0
x
0
0
0
0
0
x
0
x
0
x
x
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
x
x
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
x
0
0
0
0
0
x
0
x
0
0
x
0
0
0
0
0
x
0
x
0
0
x
0
0
0
0
0
x
0
x
0
0
x
0
0
0
0
0
x
0
x
0
0
x
0
0
0
0
0
x
0
x
0
0
x
0
0
x
0
x
0
0
0
x
0
0
x
0
0
0
0
0
x
0
x
0
0
x
0
0
0
0
0
x
0
x
0
x
0
x
0
0
0
0
x
0
0
0
0
x
x
0
0
x
0
0
0
0
0
x
0
x
0
0
x
0
0
0
0
0
x
0
x
0
?
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
?
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
x
0
0
0
0
x
0
0
0
x
0
x
0
0
0
x
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
?
x
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
?
?
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
x
x
0
0
?
0
?
?
?
0
0
0
0
0
0
0
0
0
x
0
0
?
0
0
0
0
x
0
0
0
0
x
x
0
0
x
x
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
x
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
x
x
0
0
0
0
0
x
0
x
x
0
0
0
0
x
x
0
0
0
0
0
?
x
0
0
0
0
?
0
0
0
0
0
0
0
0
0
?
?
0
0
0
0
0
0
0
0
x
0
0
0
0
0
x
?
x
0
0
x
0
x
0
0
0
0
0
x
x
0
x
0
0
x
0
x
x
x
x
0
x
0
0
x
0
0
0
0
0
0
0
0
0
0
0
x
0
0
x
0
0
x
0
0
0
0
0
0
x
x
x
x
x
0
x
0
0
0
0
x
0
0
0
x
0
0
0
0
0
x
0
0
x
0
0
0
0
0
0
x
x
x
x
x
0
x
0
0
0
0
x
0
0
0
x
0
0
0
0
0
x
0
0
x
0
0
x
0
0
0
x
x
x
x
x
0
x
0
x
0
0
0
0
0
x
0
0
0
x
0
x
0
0
x
0
0
0
0
0
0
x
0
x
x
x
x
0
0
x
x
x
0
0
0
x
?
x
0
0
x
0
0
0
0
0
x
?
x
0
x
0
0
x
x
0
0
x
0
0
x
x
0
0
?
x
0
?
x
0
0
0
0
0
0
0
x
0
0
x
0
0
0
0
0
0
?
0
0
0
0
0
0
x
0
0
0
x
x
?
0
0
0
x
?
0
0
0
0
0
0
?
x
x
x
0
x
0
0
?
0
0
0
0
x
0
0
0
0
0
0
0
x
x
x
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
x
0
x
0
0
0
x
x
x
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
x
x
0
0
0
0
x
x
x
0
x
0
x
x
x
0
x
0
0
0
0
0
0
x
x
x
0
0
x
0
0
0
0
0
0
x
x
x
0
0
0
0
x
0
x
0
x
0
0
0
0
0
x
0
x
x
0
0
x
0
?
?
0
0
0
0
?
x
0
0
0
x
0
x
0
x
0
?
0
?
?
x
x
x
x
?
0
x
0
x
0
x
x
?
x
0
0
0
0
x
x
x
0
0
0
x
x
0
0
x
0
x
0
x
x
x
x
x
0
x
x
x
0
x
0
0
0
0
x
0
x
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
x
0
0
x
x
0
0
0
0
0
0
x
x
0
0
0
x
0
0
0
0
x
0
0
x
0
0
x
x
0
0
0
0
x
0
x
x
0
0
0
0
x
0
0
0
0
0
x
x
0
x
0
0
?
0
0
0
0
0
0
?
0
?
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
?
0
x
0
?
0
0
0
x
0
0
x
x
0
0
0
0
0
?
0
0
0
0
0
0
0
0
0
0
0
x
x
0
0
0
?
0
?
0
0
0
?
?
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
x
0
0
0
0
0
0
?
?
0
x
0
0
x
?
0
0
0
0
x
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
x
x
?
0
0
x
?
0
0
0
0
x
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
?
0
x
0
0
0
x
0
x
0
?
0
0
0
?
0
x
...
Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block
? - Unknown Block
x - Potentially Malicious Block