PUP.Patcher.AC

Analysis Report

General information

Family Name: PUP.Patcher.AC
Signature status: No Signature

Known Samples

MD5: f6cf29daa37690a1662d14b037b9857f
SHA1: 5629a7c92ee0a3c320737195d244e9c5dcbb0e2c
SHA256: 37ECEF6C3D87B8943DBCE1757900926BE0F953CA1EC3843C64663C0B33A74F7C
File Size: 8.43 MB, 8427989 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description ExcelToSqlLiteDb
File Version 1.0.0.0
Internal Name IRG2022.exe
Legal Copyright Copyright © 2021
Original Filename IRG2022.exe
Packager Turbo Studio 21
Packager Version 22.3.5
Product Name ExcelToSqlLiteDb
Product Version 1.0.0.0
Vm Version 22.3.4

File Traits

  • big overlay
  • x86
  • Xenocode

Block Information

Total Blocks: 39
Potentially Malicious Blocks: 0
Whitelisted Blocks: 39
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Patcher.AC
  • Stealer.A

Windows API Usage

Category API
Process Manipulation Evasion
  • NtWriteVirtualMemory

Trending

Most Viewed

Loading...