PUP.Somoto.A

Analysis Report

General information

Family Name: PUP.Somoto.A
Signature status: Self Signed

Known Samples

MD5: 869c8bd31d784bb9a642f6e62430fef9
SHA1: e833ec5e5f8909402d1020e17972cea82627122c
SHA256: 6D0D911CB3FCC3744CF418E414FD3DCD00E351847E71BA715F9A4C0104E3491E
File Size: 132.20 KB, 132203 bytes
MD5: ee13a94f2b410bb6d2e7e933ef77887c
SHA1: 29fefb03e803e6430d7d0eaa47324a3691ca13f8
SHA256: F1668B0851CA074893FF8FA2924910269FCFCFC3CBBD627F6B67ACFBB748CDAA
File Size: 125.41 KB, 125408 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Somoto Ltd.
Company Website www.FileBulldog.com
File Description Powered by BetterInstaller
File Version
  • 1.2.0.0
  • 1.0
Product Name
  • Better Installer
  • eType
Product Version 1.0

Digital Signatures

Signer Root Status
DSNR VeriSign Class 3 Code Signing 2010 CA Self Signed

File Traits

  • Installer Version
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nsha719.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsha72a.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\tempdir\betterinstaller.exe Generic Write,Read Attributes
c:\users\user\appdata\local\tempdir\config.ini Generic Write,Read Attributes
c:\users\user\appdata\local\tempdir\config.ini Synchronize,Write Attributes

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

"C:\Users\Lbqhdndy\AppData\Local\TempDIR\betterinstaller.exe" /affid "etype" /id "etype" /name "eType"

Trending

Most Viewed

Loading...