PUP.Taobao

Analysis Report

General information

Family Name: PUP.Taobao
Signature status: No Signature

Known Samples

MD5: 44b7d1857ca7962f3d4b1734e6d3182f
SHA1: d60db830aaa6588f1318439873f984e338e32c15
SHA256: C0E88C8F4B0FAB077C86CA2B69EB554E5A0601DB2E204C3B2A505F9E846F0993
File Size: 1.61 MB, 1609995 bytes
MD5: 53f66846d3429fe5b00f7c927bf5d83d
SHA1: bedcff1808883d9ac4483bf86ea2332e07fe02c4
SHA256: 96C9B487D8CFED1D0FC09F44B3249AFE679C63110767A4C7C26F25C84AE4623B
File Size: 4.22 MB, 4215200 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments 此安装程序由 Inno Setup 构建。
Company Name 枫叶素材
File Description
  • HitPaw Watermark Remover Setup
  • Topaz Video AI 星光补丁 Setup
Product Name
  • HitPaw Watermark Remover
  • Topaz Video AI 星光补丁
Product Version
  • 7.1.1
  • 2.0

Files Modified

File Attributes
c:\users\user\appdata\local\temp\is-1t0v5.tmp\_isetup\_iscrypt.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-1t0v5.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-8qbqh.tmp\_isetup\_iscrypt.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-8qbqh.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-99nvf.tmp\d60db830aaa6588f1318439873f984e338e32c15_0001609995.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-k75nf.tmp\bedcff1808883d9ac4483bf86ea2332e07fe02c4_0004215200.tmp Generic Write,Read Attributes

Windows API Usage

Category API
Process Shell Execute
  • CreateProcess
User Data Access
  • GetUserObjectInformation
Keyboard Access
  • GetKeyState
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

"C:\Users\Uretmrnv\AppData\Local\Temp\is-99NVF.tmp\d60db830aaa6588f1318439873f984e338e32c15_0001609995.tmp" /SL5="$501F0,771499,725504,c:\users\user\downloads\d60db830aaa6588f1318439873f984e338e32c15_0001609995"
"C:\Users\Jomituba\AppData\Local\Temp\is-K75NF.tmp\bedcff1808883d9ac4483bf86ea2332e07fe02c4_0004215200.tmp" /SL5="$80112,3376698,725504,c:\users\user\downloads\bedcff1808883d9ac4483bf86ea2332e07fe02c4_0004215200"

Trending

Most Viewed

Loading...