PUP.Screenmate.B

Analysis Report

General information

Family Name: PUP.Screenmate.B
Signature status: No Signature

Known Samples

MD5: 52fb7d555a35ed7b9c3ea172f616108e
SHA1: db3da5584eaa577033763797ed539e74ef4ddf41
SHA256: 273FC8FAE3ADE7FD12ACAB0BA94F52848E068703217137BB1BEFAA13FE232ABC
File Size: 495.62 KB, 495616 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 771
Potentially Malicious Blocks: 285
Whitelisted Blocks: 477
Unknown Blocks: 9

Visual Map

0 ? 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 x x x x x x x x x x x x 0 x x x ? ? 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x ? x x x x 0 x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x 0 0 x 0 x x x x x 0 x x x 1 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 x 0 x 0 0 0 x x 0 x 0 0 0 x 0 x 0 x x x x x x 0 x x x x x x 0 0 0 0 x x x x x x x x x x 0 x x x x x 0 x 0 x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x x x x x 0 x 0 x x x x ? x x x x x x 0 x 0 x x x x x x x x x x x x x x 0 x ? x 0 0 0 x 0 x x x 0 0 x x x x x x x x x x x x x x x x x ? 0 x x x x x x 0 x x x x 0 0 x x x x x x x x x x x x x x x x ? 0 x x x x x x x 0 x x x x x x x 0 x x x x x 0 x x x 0 0 0 x x x 0 x 0 0 0 x 0 0 x x ? 0 x x x x x x x x x x x x x x x x x x x x x x 0 0 x x 0 x x x x 0 x 0 0 x x x x x x x 0 0 x x x x x x x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Screenmate.B

Files Modified

File Attributes
c:\users\user\appdata\local\temp\a822\a93c.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\a822\a94c.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\a822\aa1a.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\a822\aa3a.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\a822\aa3b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\a822\htpa94d.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\adtools, inc.\temp::dir C:\Users\Xsnerutg\AppData\Local\Temp\A822\ RegNtPreCreateKey
HKCU\software\adtools, inc.\connection::installed  RegNtPreCreateKey
HKCU\software\adtools, inc.\userinfo::identifier 9f0ce867-42e0-469a-ac14-5cb824912474 RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • OutputDebugString
Network Winsock2
  • WSAStartup
Network Winsock
  • closesocket
  • connect
  • gethostbyname
  • send
  • socket

Trending

Most Viewed

Loading...