PUP.MSIL.Bulz.RN

PUP.MSIL.Bulz.RN是安全软件用于识别使用 .NET 框架编写的潜在有害程序 (PUP) 的一个检测名称,其名称中的“MSIL”部分即表明了这一点。被此检测标记的程序通常不属于传统病毒或高破坏性恶意软件,但由于它们往往表现出侵入性、欺骗性或侵犯隐私的行为,因此被认为是有害的。由于尚未确认此特定检测的详细技术细节,以下信息描述了与此类威胁相关的典型行为。

这种威胁通常会造成什么后果?

被识别为 PUP.MSIL.Bulz.RN 的程序通常以捆绑或游走在恶意软件边缘的形式出现,它们会与其他软件一起安装到系统中,用户往往对此毫不知情。这类程序通常会尝试修改浏览器设置、在网页中插入广告、重定向搜索查询,或安装用户未明确要求的工具栏和扩展程序。在许多情况下,这些程序的主要目的是通过广告网络、联盟营销或数据收集等方式为开发者牟利,而非为最终用户提供任何实质性的益处。

此类中的某些潜在有害程序 (PUP) 也可能运行消耗系统资源的后台进程、显示持续弹出通知,或者故意使用户难以通过正常方式找到并卸载它们。

它通常是如何进入电脑的

这类潜在有害程序 (PUP) 通常通过软件捆绑传播,它们与免费下载的软件(例如媒体播放器、PDF 转换器、系统实用程序或盗版软件)捆绑在一起。用户如果匆忙完成安装向导而没有仔细查看每个步骤,就可能在不知不觉中同意安装这些额外的程序。其他常见的传播方式包括欺骗性广告、虚假的软件更新提示,以及文件共享或流媒体网站上误导性的“下载”按钮,这些按钮会诱使用户下载不需要的程序,而不是他们想要访问的内容。

用户面临的风险

虽然潜在有害程序 (PUP) 通常比恶意软件危害小,但它们仍然存在一些风险。这些风险包括系统性能下降、侵入式和过度广告、浏览器主页或默认搜索引擎被恶意更改,以及通过它们显示的广告可能接触到其他恶意内容。某些 PUP 还可能收集浏览习惯、搜索历史记录或其他使用数据并与第三方共享,从而引发隐私担忧。

感染迹象

系统上可能存在此类潜在有害程序的常见迹象包括:计算机或浏览器明显变慢、浏览器设置发生意外更改、出现未经有意安装的新工具栏或扩展程序、即使浏览器未处于活动状态也频繁出现弹出式广告,以及已安装应用程序列表或系统启动项中出现不熟悉的程序。

如何做好防护

为了降低遇到此类恶意程序的风险,用户应始终直接从官方或可信来源下载软件,仔细阅读安装向导的每个步骤,并通过选择“自定义”或“高级”安装选项(而非默认设置)来取消任何捆绑安装。保持操作系统和浏览器更新、避免点击可疑的下载链接或弹出提示,并定期检查已安装的程序和浏览器扩展程序,也有助于及早发现恶意软件。运行信誉良好的安全软件并定期进行系统扫描仍然是检测和清除此类程序的有效方法,可以防止它们造成进一步的破坏。

分析报告

一般信息

姓: PUP.MSIL.Bulz.RN
签名状态: No Signature

已知样本

MD5: 95759f70ce5a8fd5b6e8caa195f277f6
SHA1: 41f0ba0cbe36e62eb1114fade3165cae38ada767
SHA256: 42C29A6CA7C25789888CE33992176765781F05FBFC1348BC68260F4AC90F1445
文件大小: 45.57 KB,45568字节

Windows 可移植可执行文件属性

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

文件图标

Windows PE 版本信息

姓名 价值
Assembly Version 1.0.0.0
Comments java环境变量配置工具
Company Name Microsoft
File Description java环境变量配置工具
File Version 1.0.0.0
Internal Name Jdk_Path_Config.exe
Legal Copyright Copyright © scimence 2022
Original Filename Jdk_Path_Config.exe
Product Name Jdk_Path_Config
Product Version 1.0.0.0

文件特征

  • .NET
  • x86

区块信息

总区块数: 29
潜在恶意块: 10
白名单区块: 8
未知区块: 11

可视化地图

x ? ? ? 0 x x x x ? 0 x x x 0 ? ? ? ? ? ? ? x x 0 0 0 0 0
0 - 可能的保险箱
? - 未知区块
x - 潜在恶意拦截

文件已修改

文件 属性
c:\programdata\scitools\scitools.data Generic Write,Read Attributes

注册表修改

键::值 数据 API名称
HKLM\software\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
显示更多
HKLM\software\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey

Windows API 使用情况

类别 API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcCreatePortSection
  • ntdll.dll!NtAlpcCreateSectionView
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
显示更多
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueueApcThread
  • ntdll.dll!NtQueueApcThreadEx2
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetComputerName
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
Network Winsock2
  • WSAConnect
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • recv
  • send
  • setsockopt
Network Winhttp
  • WinHttpOpen
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams
Anti Debug
  • IsDebuggerPresent