Threat Database Hacktool PUP.Patcher.EA

PUP.Patcher.EA

Analysis Report

General information

Family Name: PUP.Patcher.EA
Packers: UPX
Signature status: No Signature

Known Samples

MD5: 256319ff3be3bd072bd5844713802718
SHA1: fe67fec4aa818a27a678dca7c15b82c71b800168
File Size: 5.90 KB, 5904 bytes
MD5: 7a3576dd40148f2b99f2194237ab3892
SHA1: 28c74c18b6e75d382e1e10efb7ec498a63b9a536
File Size: 5.73 KB, 5734 bytes
MD5: 5f5d35295d14c690bd645e5e52710687
SHA1: feddef90f9d2ac0f6437c849cb2182dca02cd702
SHA256: CCA477F240A7BB9E6E526657CBBE495E7646E222C11105912799F728B76C9679
File Size: 3.42 MB, 3415992 bytes
MD5: 7edab4f4f1f8c33113242b8d12a8b893
SHA1: 59146950f83c2132c281bf9ce6c967ceb8edde3f
SHA256: 2DDAC6A6631812A6192F36F630F3BAB7DF4BA1F7D29E87F5BB09561EFD0AD9D0
File Size: 5.75 KB, 5752 bytes
MD5: 87fbcf0ac9f21c09d065f6908cc0ee87
SHA1: c2fd13ba3be4a2ad22816385df39e4dca74265a0
SHA256: 19B3251E3160AE41DACC20510CB7F01D369C64085858042AF7F6BBDBE9D237C9
File Size: 8.15 KB, 8153 bytes
Show More
MD5: 7fcd95d30a57be6922b56ac22f644fbd
SHA1: 0240f0d0016184d4296ffae34e81bd12a49dacf4
SHA256: 4D2C105FE56FC0E33F71C961788CFB21969F07F3E7B7424821F70A477607D595
File Size: 6.66 KB, 6656 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Description File created by ScAEvoLa's PatchEngine
File Version
  • 1.33
  • 1.32

File Traits

  • .UPX
  • 2+ executable sections
  • HighEntropy
  • packed
  • x86

Block Information

Total Blocks: 6
Potentially Malicious Blocks: 4
Whitelisted Blocks: 2
Unknown Blocks: 0

Visual Map

x 0 0 x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Patcher.EA

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Trending

Most Viewed

Loading...