PUP.Patcher.AA

Analysis Report

General information

Family Name: PUP.Patcher.AA
Packers: UPX
Signature status: No Signature

Known Samples

MD5: 6a20d84542b0d698f318b999f25f700d
SHA1: 95918601a474f5c154a96d4df651ea7fa7bf880e
SHA256: 6C63666D800033135943838418B61F80A56F0D3EBBD44F06B39DE3FA8E40F314
File Size: 32.61 KB, 32611 bytes
MD5: a1004866f0ddb04267890661a6f6ae02
SHA1: 5a4ffcca7c53f6d0ed7e4b636ff8455e9e87d844
SHA256: E56BAB2A82BA55D786B888AC77E68CF3CFEC4CE3FBE52181E1AF7A0A5F957056
File Size: 53.35 KB, 53350 bytes
MD5: cc27baa93eb41f17dd639b4cfd401f3d
SHA1: af05c300faf94fbf64ed05ae40115ec11da16dd6
SHA256: 467B2019D1E5965DDFE44414EAF036D97BA4921FA53F6A99BC1980EAA69F8D80
File Size: 22.45 KB, 22455 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • .UPX
  • 00 section
  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • packed
  • UPX!
  • x86

Block Information

Total Blocks: 35
Potentially Malicious Blocks: 20
Whitelisted Blocks: 15
Unknown Blocks: 0

Visual Map

x x 0 x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Patcher.AA

Files Modified

File Attributes
c:\users\user\downloads\3f08.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\downloads\7841.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\downloads\a8b0.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Trending

Most Viewed

Loading...