PUP.PowerRun
Table of Contents
Analysis Report
General information
| Family Name: | PUP.PowerRun |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
cf22c17ca19f7c31dbf098683d458b9c
SHA1:
1a51bd6efd4b8ddf12ff456a54f55102fbd3f986
File Size:
842.99 KB, 842994 bytes
|
|
MD5:
41e1e078871a73b1ccb5842a8517a2b8
SHA1:
9bfcb1c13dadc06128ef6fd6791dbac81f6c0210
File Size:
543.66 KB, 543661 bytes
|
|
MD5:
1a6bf240f43808ff58b98bdf3b85524c
SHA1:
d9e0b62548153f132887c39f72befcbd4b453f9c
SHA256:
E58B3F06F81E9F454922E56F20875AB5CF5A7D0F99524E02B7603F46B1F831F7
File Size:
843.73 KB, 843733 bytes
|
|
MD5:
d8949a1bdbf7b72369296f3ef39f59a1
SHA1:
1d750a9d018dd9a953b4f36bc4c5401045a32bee
SHA256:
DA011EABF65A8CFB44705B62140AC963C82E25727825E949EB81F47C806FCCBD
File Size:
899.74 KB, 899742 bytes
|
|
MD5:
5acc6239eb4321ad197f30e30bb17307
SHA1:
591e997fc3cc0a1146646057e9ddeff4aad9d10c
SHA256:
1A23326D5628EC55B9F8033CCDC1324C36D3A7536CDC7E2C44056049134E69C7
File Size:
894.02 KB, 894016 bytes
|
Show More
|
MD5:
05af406f46a08be6ebdd86c282f746e9
SHA1:
8b87d60415c0ead149be5883fb15f52a9c2e899d
SHA256:
B9DE9C1E9D6723CD6915474FB67BA878F445431CA6C0338F5F567E298E19A06B
File Size:
1.05 MB, 1054979 bytes
|
|
MD5:
75d9dd5c5da200748ad280e4d2580bba
SHA1:
623908159b8a9815db2f2e754ca691b76d22684e
SHA256:
C72D2EE2333BA87E962ADF00E441468C96B72F5609905B3C91C9758EA26E995E
File Size:
1.67 MB, 1673760 bytes
|
|
MD5:
6eb1baa41c8731fd84bcde7081f0d940
SHA1:
36dfc44315b2c5e649b1bbaea322e6ca6b1e7264
SHA256:
47E0AA5F1B337D02C800F91D5360431E5B9883299722AB25E74F6DB3ECF40B5F
File Size:
2.08 MB, 2082848 bytes
|
|
MD5:
15c3d5d3bbde6b7b20954d870adb0c7d
SHA1:
1204dba6aa49b03abb3f79b5a31101a31c1b0cb9
SHA256:
CB14A3D093C2B4B2BE0EE5E123EBAFFCD7D5F681D222F97A5341D6C6D65C1E2D
File Size:
833.56 KB, 833560 bytes
|
|
MD5:
121a7cadbeea06d5544df7786b3309f2
SHA1:
47e2188597ba3d77ff1ebb977329be21ab00e6e2
SHA256:
77F356F648B91916E9BD1711F11B67A1986FC26CEEAA915AADD53D0A266BE65A
File Size:
999.03 KB, 999033 bytes
|
|
MD5:
409e1c6995725b25551809484a8e1f45
SHA1:
00b2651355689bc73a47b523f56243a13c03dc4c
SHA256:
50436566C22D4E7AC32B9BE8D78CC5245234BE14824313B41165FF324BB07F88
File Size:
789.62 KB, 789624 bytes
|
|
MD5:
82fa1feb495fe325ee10a856ce62c2e8
SHA1:
292a7cf11809edf7860f7dc9c5da410ec946d79b
SHA256:
56DB4A91890041FC193FA87BB28B0750F6B251C904D49CAAA4298A0D9435A34E
File Size:
1.08 MB, 1076224 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have security information
- File has TLS information
- File is .NET application
- File is 32-bit executable
- File is 64-bit executable
- File is either console or GUI application
Show More
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Assembly Version |
|
| Coder | By BlueLife |
| Comments |
|
| Company Name |
|
| File Description |
|
| File Version |
|
| Internal Name |
|
| Legal Copyright |
|
| Legal Trademarks |
|
| Original Filename |
|
| Product Name |
|
| Product Version |
|
Digital Signatures
Digital Signatures
This section lists digital signatures that are attached to samples within this family. When analyzing and verifying digital signatures, it is important to confirm that the signature’s root authority is a well-known and trustworthy entity and that the status of the signature is good. Malware is often signed with non-trustworthy “Self Signed” digital signatures (which can be easily created by a malware author with no verification). Malware may also be signed by legitimate signatures that have an invalid status, and by signatures from questionable root authorities with fake or misleading “Signer” names.| Signer | Root | Status |
|---|---|---|
| AnWave Software and Simon Macer Project | AnWave Software and Simon Macer Project | Self Signed |
| Sordum Software | Sordum Software | Hash Mismatch |
File Traits
- big overlay
- HighEntropy
- WriteProcessMemory
- x64
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 275 |
|---|---|
| Potentially Malicious Blocks: | 38 |
| Whitelisted Blocks: | 237 |
| Unknown Blocks: | 0 |
Visual Map
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
x
0
0
0
0
0
0
x
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
x
0
0
0
0
0
0
x
x
x
x
x
0
0
0
0
0
0
0
0
0
x
0
x
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
x
x
x
0
x
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
x
0
x
0
x
x
x
x
0
x
x
x
x
x
x
x
x
x
0
x
x
0
0
x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Autoit
- Bitcoinminer.BDA
- Bitcoinminer.BDB
- Bitcoinminer.DJE
- Rugmi.T
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\namedpipe\gmdasllogger | Generic Write,Read Attributes |
| c:\programdata\anwaverootinstall\require\simonmacer.pfx | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7r5v6f8k.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\7r5v6f8k.tmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\powerrun.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\powerrun.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_defender | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_defender | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_defender\removedefender.reg | Generic Write,Read Attributes |
Show More
| c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_defender\removedefender.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_defender\removeshellassociation.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_defender\removeshellassociation.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_securitycomp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_securitycomp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_securitycomp\remove_securitycomp.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_securitycomp\remove_securitycomp.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\removesechealthapp.ps1 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\removesechealthapp.ps1 | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\script_run.bat | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\script_run.bat | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\disable_defender | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\disable_defender | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\disable_defender\disable_def.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\disable_defender\disable_def.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\enable_defender | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\enable_defender | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\enable_defender\enable_def.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\enable_defender\enable_def.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\firewall | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\firewall | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\firewall\add firewall menu.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\firewall\add firewall menu.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\firewall\remove firewall menu.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\firewall\remove firewall menu.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\antivirus_d.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\antivirus_d.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\defender anti-phishing_d.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\defender anti-phishing_d.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\exploit guard_d.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\exploit guard_d.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\security health_d.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\security health_d.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\smartappcontrol_d.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\smartappcontrol_d.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\windows security center_d.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\windows security center_d.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\antivirus_e.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\antivirus_e.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\defender anti-phishing_e.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\defender anti-phishing_e.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\security health_e.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\security health_e.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\windows security center_e.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\windows security center_e.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable lsa protection.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable lsa protection.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable microsoft vulnerabile driver blocklist.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable microsoft vulnerabile driver blocklist.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable smartscreen.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable smartscreen.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable uac.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable uac.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable vbs.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable vbs.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\no more delay and timeouts.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\no more delay and timeouts.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\security health.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\security health.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\windows settings page visibility.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\windows settings page visibility.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\oscdimg.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\oscdimg.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\powerrun.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\powerrun.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\disable defender and security center notifications.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\disable defender and security center notifications.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\disable defender policies.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\disable defender policies.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\disable tamper protection.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\disable tamper protection.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\lockdown windows defender security center.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\lockdown windows defender security center.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of anti-phishing services.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of anti-phishing services.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of sechealthui.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of sechealthui.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of windows defender antivirus.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of windows defender antivirus.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of windows security action center.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of windows security action center.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove defender tasks.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove defender tasks.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove security and maintenance.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove security and maintenance.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove services.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove services.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove shell association.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove shell association.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove startup entries.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove startup entries.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove windows defender firewall rules.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove windows defender firewall rules.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove windows webthreat.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove windows webthreat.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remover of defender context menu.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remover of defender context menu.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\script_run.bat | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\script_run.bat | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\winwim.cmd | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\winwim.cmd | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\powerrun.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\powerrun.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender\nomoredelayandtimeouts.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender\nomoredelayandtimeouts.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender\removedefender.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender\removedefender.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender\removeshellassociation.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender\removeshellassociation.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_securitycomp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_securitycomp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_securitycomp\remove_securitycomp.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_securitycomp\remove_securitycomp.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\removesechealthapp.ps1 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\removesechealthapp.ps1 | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\script_run.bat | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\script_run.bat | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\powerrun.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\powerrun.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\disableantivirusprotection.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\disableantivirusprotection.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\disabledefenderandsecuritycenternotifications.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\disabledefenderandsecuritycenternotifications.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\disabledefenderpolicies.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\disabledefenderpolicies.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\nomoredelayandtimeouts.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\nomoredelayandtimeouts.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\removalofwindowsdefenderantivirus.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\removalofwindowsdefenderantivirus.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\removedefendertasks.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\removedefendertasks.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\removerofdefendercontextmenu.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\removerofdefendercontextmenu.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\removeservices.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\removeservices.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\removeshellassociation.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\removeshellassociation.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\removesignatureupdates.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\removesignatureupdates.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\removestartupentries.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\removestartupentries.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\removewindowswebthreat.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\removewindowswebthreat.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\windowssettingspagevisibility.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\windowssettingspagevisibility.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\disabledevdriveprotection.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\disabledevdriveprotection.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\disablelsaprotection.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\disablelsaprotection.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\disablemaintenancetaskreportinginsecurityhealthui.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\disablemaintenancetaskreportinginsecurityhealthui.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\disablemicrosoftvulnerabiledriverblocklist.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\disablemicrosoftvulnerabiledriverblocklist.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\disablesmartscreen.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\disablesmartscreen.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\disablespynettelemetry.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\disablespynettelemetry.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\disablesystemmitigations.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\disablesystemmitigations.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\disabletamperprotection.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\disabletamperprotection.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\disableuac.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\disableuac.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\disablevbs.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\disablevbs.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\exploitguard_d.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\exploitguard_d.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\mitigationoffaulttorelantheap.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\mitigationoffaulttorelantheap.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\removalofanti-phishingservices.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\removalofanti-phishingservices.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\remove and disable microsoft pluton.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_securitycomp\remove and disable microsoft pluton.reg | Synchronize,Write Attributes |
86 additional files are not displayed above.
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 俆ꦎ⚖ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 竞⚛ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | ಲ䪩茔ǜ | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Anti Debug |
|
| User Data Access |
|
| Process Manipulation Evasion |
|
| Process Shell Execute |
|
| Syscall Use |
Show More
130 additional items are not displayed above. |
| Service Control |
|
| Keyboard Access |
|
| Other Suspicious |
|
| Cert Store Read |
|
| Cert Store Write |
|
| Encryption Used |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
.\Script_Run.bat
|
WriteConsole: ------ Defender
|
WriteConsole: Select an option
|
WriteConsole:
|
WriteConsole: Do you want to r
|
Show More
WriteConsole: If you PC have a
|
WriteConsole: After confirmati
|
WriteConsole: A backup and/or
|
WriteConsole: [Y] Remove Windo
|
WriteConsole: [A] Remove Windo
|
WriteConsole: [S] Disable All
|
C:\WINDOWS\system32\choice.exe choice /C:yas /N
|
WriteConsole: (NULL)
|
C:\Users\Sqljlniy\AppData\Local\Temp\{2C6E2BE6-1CB4-4E15-8576-CBF76CA4FD6A}\Script_Run.bat
|
WriteConsole: Defender Remover
|
WriteConsole: 592ce29595c2aa20e294a4e28c90e295
|
WriteConsole: 4e2ce29494e2959720e294a4e28c90e2
|
WriteConsole: 452ce29595c2aa20e294a4e28c90e295
|
WriteConsole: 482ce29595c2aa20e294a4e28c90e295
|
WriteConsole: 492ce29595c2aa20e294a4e28c90e295
|
WriteConsole: 462ce29595c2aa20e294a4e28c90e295
|
WriteConsole: 472ce29595c2aa20e294a4e28c90e295
|
WriteConsole: 522ce29494e2959720e294a4e28c90e2
|
WriteConsole: 552ce29595c2aa20e294a4e28c90e295
|
WriteConsole: 4a2ce29595c2aa20e294a4e28c90e295
|
WriteConsole: e2959de29692e294bce2949ce2959fe2
|
WriteConsole: e29691cea6e2959de29599e2959fe295
|
C:\WINDOWS\system32\mode.com mode con cols=70 lines=25
|
WriteConsole: Access is denied
|
WriteConsole: e2959fceb4e295a4c3ade29598c2b1e2
|
WriteConsole: e295a9e2959fe29596c2b1e295a5c2ac
|
WriteConsole: e2959acf84e295a3e2889ae29480cf80
|
WriteConsole: 28e294a4e295a6e2959ce294bce29692
|
WriteConsole: e2959ae29596e2959ae295a7e29594e2
|
WriteConsole: e2959cc2bfe295a5ce98e295a9e295a3
|
WriteConsole: 5b595d20e295a5e2959ee29482c2b220
|
WriteConsole: 5b415d20e295a5e2959ee29482c2b220
|
WriteConsole: 5b535d20e2959ce2889ae29599e2949c
|