PUP.PC Accelerator.BA

Analysis Report

General information

Family Name: PUP.PC Accelerator.BA
Signature status: No Signature

Known Samples

MD5: 82706057f27370d4f17bfd8dc576fcce
SHA1: 2814d822fe7fb6886b7a354859c64d8302ea8a6f
SHA256: B5A33D71AFB7A8FB2DB052E9C37160F769C2F5A28769BE76D0D32184FBE0051A
File Size: 121.02 KB, 121022 bytes
MD5: f779d1311d14cb9fe5a664214354cbe4
SHA1: a496ce4daa9a4849325fc95f89ee3b6e06bef667
SHA256: FABD583AB302171A065FC918C8CEDA62E51EBDE295BCB804F9C1340E5AF722E7
File Size: 121.03 KB, 121025 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name ProtectorsOfRealm Code
File Description ProtectorsOfRealm
File Version 1.0.0.1
Legal Copyright © ProtectorsOfRealm Code 2021
Product Name ProtectorsOfRealm
Product Version
  • 1.0.0.1!10/17/2021@05:49:47
  • 1.0.0.1!9/6/2021@08:57:09

File Traits

  • dll
  • HighEntropy
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nskba3e.tmp\oupdater.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsp4169.tmp\oupdater.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~nsua.tmp\un_a.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Rizgnsxv\AppData\Local\Temp\~nsuA.tmp\Un_A.exe RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Rizgnsxv\AppData\Local\Temp\~nsuA.tmp\Un_A.exe\??\C:\Users\Rizgnsxv\AppData\Local\Temp\~nsuA.tmp RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old5af52*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old5af62*1\??\C:\P RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Shell Execute
  • CreateProcess

Shell Command Execution

"C:\Users\Rizgnsxv\AppData\Local\Temp\~nsuA.tmp\Un_A.exe" _?=c:\users\user\downloads\
"C:\Users\Pfukqopu\AppData\Local\Temp\~nsuA.tmp\Un_A.exe" _?=c:\users\user\downloads\

Trending

Most Viewed

Loading...