PUP.OSMonitor

Analysis Report

General information

Family Name: PUP.OSMonitor
Signature status: Root Not Trusted

Known Samples

MD5: bed21863e6975cddd29013f572a7da88
SHA1: 192bee7121cad2dbb115a6e67c18be2e3a67b8fa
SHA256: 9AE2D9D5174B7FB4C7342BFF22E9813136BC52BCC6D0047ECA6CF2B7865C4846
File Size: 932.62 KB, 932616 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Microsoft
File Version 10.02.0041
Internal Name WorkWinLm
Legal Trademarks Client
Original Filename WorkWinLm.exe
Product Name Client
Product Version 10.02.0041

Digital Signatures

Signer Root Status
Nanjing Wangya Computer Co.,Ltd. thawte Primary Root CA Root Not Trusted

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx

Trending

Most Viewed

Loading...