PUP.TrueDownloader.A

Analysis Report

General information

Family Name: PUP.TrueDownloader.A
Signature status: Root Not Trusted

Known Samples

MD5: 8cbc39e9b073972d7bbf835ae99fbc68
SHA1: 86104cdf44da402b01955eab94947f89cb58a283
SHA256: 911360E2C05F73F334717FC833C6C3ABE629E222EE57AF770E08EF063557A602
File Size: 337.14 KB, 337136 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Digital Signatures

Signer Root Status
File Downloader AddTrust External CA Root Root Not Trusted

File Traits

  • dll
  • x86

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nstdc2b.tmp\avd.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nstdc2b.tmp\header.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nstdc2b.tmp\nsdialogs.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nstdc2b.tmp\system.dll Generic Write,Read Attributes

Windows API Usage

Category API
Process Manipulation Evasion
  • ReadProcessMemory
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Trending

Most Viewed

Loading...