PUP.Patcher.D

Threat Scorecard

Popularity Rank: 3,857
Threat Level: 10 % (Normal)
Infected Computers: 17,304
First Seen: July 24, 2009
Last Seen: January 25, 2026
OS(es) Affected: Windows

Aliases

4 security vendors flagged this file as malicious.

Antivirus Vendor Detection
McAfee-GW-Edition Trojan.Patched.ET
McAfee+Artemis Artemis!0DE18690E422
AntiVir TR/Patched.ET
a-squared Trojan.Patched!IK

SpyHunter Detects & Remove PUP.Patcher.D

File System Details

PUP.Patcher.D may create the following file(s):
# File Name MD5 Detections
1. ctfmon.exe 0de18690e4223998e471048889f09b8b 239

Analysis Report

General information

Family Name: PUP.Patcher.D
Packers: UPX
Signature status: No Signature

Known Samples

MD5: 4c19d0aeff4032ef636ef2f83c3a4f5b
SHA1: e65b8fad81a111d5ed952a1cab2d894fd10ee89d
File Size: 601.09 KB, 601088 bytes
MD5: 3b06302a18e8d55f740044a6b0d58412
SHA1: 847540e45dd7c544edcbf499c8b167ab52d2ef9c
SHA256: 7E148E5DDB89EF038991EB5F97E45FD49DD9817B2140AB6A0AF7C9E40C5EF65A
File Size: 59.90 KB, 59904 bytes
MD5: 748af73ccc24c62d1b665f171b88b54f
SHA1: c0ea32668caf252a92177b89b299c3fa144aff10
SHA256: 171FED17E2350D0A607F70E96C2B7EF06174B039516DCDB099AE293A2939C7DC
File Size: 1.62 MB, 1620480 bytes
MD5: c1520f608fe261be6e5869ca67b69fcc
SHA1: d8ba170d6785143972868d30ea0808201aeaf354
SHA256: F55006D6B71B8566046C53FAD887B3C3731777A67931A98D034DAB9069B58C40
File Size: 324.10 KB, 324096 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • No Version Info
  • ntdll
  • packed
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 403
Potentially Malicious Blocks: 152
Whitelisted Blocks: 248
Unknown Blocks: 3

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x 0 0 x 0 0 x 0 0 x 0 x 0 0 0 x x 0 0 x 0 x x x 0 0 x x 0 x x x x 0 x x 0 x 0 x 0 x 0 x 0 x x x x x x x 0 0 x x x x x x x x x 0 0 x x x x x x x x x x x x x x x 0 x x x 0 x 0 0 0 0 0 x 0 x 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x x 0 0 0 0 x 0 0 0 x 0 x x x x x x x x 0 0 x 0 x x 0 0 x x 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 x 0 x 0 x x x x x x x x x x x x x x x 0 x x 0 0 x x x x x x x 0 x x ? x ? x x x x x x x x 0 0 x x 0 x x x x 0 x x x x x x x x ? 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\downloads\temp\shsandbox-win32.dll-5.22.1.9999-x86.dmp Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Related Posts

Trending

Most Viewed

Loading...