PUP.OmniTweak

Analysis Report

General information

Family Name: PUP.OmniTweak
Signature status: Root Not Trusted

Known Samples

MD5: bf56c52618efdbe595dda65c2dbe0d47
SHA1: 1abc52074bf7c200b06ebb09b898328bb5c1faab
SHA256: 051C8AEADD77990426BF0E17FAE4DF4465C3B714CC8005A6615D5092E3A2FFFA
File Size: 5.88 MB, 5881016 bytes
MD5: 88b80e2436067f58e0689892cb9025b2
SHA1: 258427cd48565ec0b649105512368619968d9afe
SHA256: E7B436E2AF217376A342D1E30341A4418D6DEB34CD926AB1215E9C8723FD4070
File Size: 3.53 MB, 3531136 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • This installation was built with Inno Setup.
  • This installation was built with InstallAware: http://www.installaware.com
File Description
  • DriverUpdaterPro Installation
  • DriverUpdater Setup
File Version
  • 10.1.0.31
  • 10.0.0.0
Legal Copyright All rights reserved
Product Name
  • DriverUpdater
  • DriverUpdaterPro
Product Version
  • 10.1.0.31
  • 10.0.0.0 0

Digital Signatures

Signer Root Status
oTweak Software, LLC GlobalSign Root Not Trusted
oTweak Software LLC thawte Primary Root CA Root Not Trusted

Files Modified

File Attributes
c:\users\user\appdata\local\temp\is-kcj8p.tmp\258427cd48565ec0b649105512368619968d9afe_0003531136.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\lang.loc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mia.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mia1\installaware.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mia561f.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\driverupdaterpro.msi Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\driverupdaterpro.msi Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\192815f8 Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\192815f8\c34f8049 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\192815f8\c34f8049\lsvgauge_d2009.bpl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\192815f8\c34f8049\lsvgauge_d2009.bpl Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\2a07891a Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\2a07891a\c34f8049 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\2a07891a\c34f8049\xmlrtl200.bpl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\2a07891a\c34f8049\xmlrtl200.bpl Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\2aa630a Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\2aa630a\c34f8049 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\2aa630a\c34f8049\rtflabel_d7.bpl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\2aa630a\c34f8049\rtflabel_d7.bpl Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\35d6aa01 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\35d6aa01\b13d7bc4 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\35d6aa01\b13d7bc4\unzip32.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\35d6aa01\b13d7bc4\unzip32.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\35e820c1 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\35e820c1\c34f8049 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\35e820c1\c34f8049\rtl200.bpl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\35e820c1\c34f8049\rtl200.bpl Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\3897f479 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\3897f479\71b86121 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\3897f479\71b86121\ins64.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\3897f479\71b86121\ins64.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\415f9294 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\415f9294\6373bd03 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\415f9294\6373bd03\driverupdaterpro.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\415f9294\6373bd03\driverupdaterpro.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\42804292 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\42804292\b13d7bc4 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\42804292\b13d7bc4\unzip.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\42804292\b13d7bc4\unzip.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\4fa164fc Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\4fa164fc\5dd183bc Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\4fa164fc\5dd183bc\segoeuib.ttf Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\4fa164fc\5dd183bc\segoeuib.ttf Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\8d3bb745 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\8d3bb745\c34f8049 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\8d3bb745\c34f8049\inet200.bpl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\8d3bb745\c34f8049\inet200.bpl Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\8e2fe17d Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\8e2fe17d\c34f8049 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\8e2fe17d\c34f8049\vclimg200.bpl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\8e2fe17d\c34f8049\vclimg200.bpl Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\9b3ea70e Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\9b3ea70e\c34f8049 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\9b3ea70e\c34f8049\tbuttonlabel.bpl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\9b3ea70e\c34f8049\tbuttonlabel.bpl Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\9c192fea Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\9c192fea\c34f8049 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\9c192fea\c34f8049\const.dat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\9c192fea\c34f8049\const.dat Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\a1267bf8 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\a1267bf8\6373bd03 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\a1267bf8\6373bd03\dupsys.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\a1267bf8\6373bd03\dupsys.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\a5ef998b Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\a5ef998b\5dd183bc Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\a5ef998b\5dd183bc\segoeui.ttf Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\a5ef998b\5dd183bc\segoeui.ttf Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\b89e9544 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\b89e9544\c34f8049 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\b89e9544\c34f8049\lang.dat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\b89e9544\c34f8049\lang.dat Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\ba7ffb98 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\ba7ffb98\c34f8049 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\ba7ffb98\c34f8049\vclx200.bpl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\ba7ffb98\c34f8049\vclx200.bpl Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\f5200477 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\f5200477\c34f8049 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\f5200477\c34f8049\vcl200.bpl Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\f5200477\c34f8049\vcl200.bpl Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\mmsi.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\mmsi.dll\mmsiexec.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\offline\mmsi.dll\mmsiexec.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\{5f207e73-153d-47f5-bf8f-6c4dc4575783} Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\data\{5f207e73-153d-47f5-bf8f-6c4dc4575783} Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\driverupdaterpro.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\driverupdaterpro.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\driverupdaterpro.msi Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\driverupdaterpro.msi Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\driverupdaterpro.res Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\driverupdaterpro.res Synchronize,Write Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\mia.lib Generic Write,Read Attributes
c:\users\user\appdata\local\temp\mia561f.tmp\mia.lib Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\applications\1abc52074bf7c200b06ebb09b898328bb5c1faab_0005881016::ishostapp RegNtPreCreateKey
HKLM\software\classes\applications\driverupdaterpro.exe::ishostapp RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Other Suspicious
  • AdjustTokenPrivileges
User Data Access
  • GetUserObjectInformation

Shell Command Execution

.\DriverUpdaterPro.exe /m="c:\users\user\DOWNLO~1\1ABC52~1" /k=""
"C:\Users\Esflnlas\AppData\Local\Temp\is-KCJ8P.tmp\258427cd48565ec0b649105512368619968d9afe_0003531136.tmp" /SL5="$10272,3109499,72192,c:\users\user\downloads\258427cd48565ec0b649105512368619968d9afe_0003531136"

Trending

Most Viewed

Loading...