PUP.SkyWebSearch.B

Analysis Report

General information

Family Name: PUP.SkyWebSearch.B
Signature status: No Signature

Known Samples

MD5: 9c1d1683b827d394e34fd5c27f60fbc3
SHA1: 78eebf80238ad555bf2b110b9f7429cfd570bb14
SHA256: E0C83DADD1D2297BA6756D797F9A96C79C818302113BD87B0B9FF1F327B0D722
File Size: 2.65 MB, 2648978 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
File Description SaveTubeVideo Setup
Product Name SaveTubeVideo

File Traits

  • dll
  • HighEntropy
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\is-58vid.tmp\78eebf80238ad555bf2b110b9f7429cfd570bb14_0002648978.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-bdkk1.tmp\_isetup\_regdll.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-bdkk1.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-bdkk1.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-bdkk1.tmp\browserstartpage.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-bdkk1.tmp\transport_dll.dll Generic Write,Read Attributes

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
User Data Access
  • GetUserObjectInformation

Shell Command Execution

"C:\Users\Enhjtyks\AppData\Local\Temp\is-58VID.tmp\78eebf80238ad555bf2b110b9f7429cfd570bb14_0002648978.tmp" /SL5="$90368,2409001,53248,c:\users\user\downloads\78eebf80238ad555bf2b110b9f7429cfd570bb14_0002648978"

Trending

Most Viewed

Loading...