PUP.Bat2Exe.D

Analysis Report

General information

Family Name: PUP.Bat2Exe.D
Signature status: No Signature

Known Samples

MD5: a152e1fb1d58fc77fa3975016dc510a9
SHA1: 82820c1458af93019e83228220899c081085a2ad
SHA256: 836EF54253CC2340C7A457FA7A3BEFA89B3CB5EF19D13FB181A266C8B54A94F1
File Size: 128.39 KB, 128393 bytes
MD5: f46025a5bc13859ab8f444fda4c6471c
SHA1: a386bccfaef450bcc14b7c12d9a9a3def404f14b
SHA256: BD2E810760A41A5F95FD50E94C88FB77919E25352D1C28E00C326E486138BD68
File Size: 198.49 KB, 198485 bytes
MD5: aa59a99476bf427b808db64b2afabc2b
SHA1: 51450661f9e7d36ef7f6867446509d817380c9a6
SHA256: 316836F7B44779BE2208806AC2060BEDC945C243BCE4C03FF5D59B7EA85227EB
File Size: 69.81 KB, 69805 bytes
MD5: e94b50124dd8eef6b61aad131f3bcbb9
SHA1: 763a8296d62edd7b4a86528180dd61157a87fb87
SHA256: 29CDD40ABA66F90D3877300A9983CD31B2D46BF4CA5A8535CA227E2D171E7160
File Size: 685.07 KB, 685073 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
Company Name
  • TipsWindows7y8, Inc
  • UniversitÚ Grenoble Alpes
  • Your Company
File Description
  • Activador para Mirillis Action!
  • Loic LEFORESTIER
  • Product Description
File Version
  • 24.11.22.0
  • 2.0
  • 1.0.0.0
Legal Copyright
  • Copyright Info
  • © TipsWindows7y8, Agosto 2014
Product Name
  • MDT Software Install
  • MiAct!Act.V2.0
  • Product Name
Product Version
  • 24.11.22.0
  • 2.0
  • 1.0.0.0

File Traits

  • Installer Manifest
  • Installer Version
  • No Version Info
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\is-csag1.tmp\763a8296d62edd7b4a86528180dd61157a87fb87_0000685073.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ytmp\t25782ers\user\downloads\.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ytmp\t25782ers\user\downloads\.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ytmp\t30484ers\user\downloads\.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ytmp\t30484ers\user\downloads\.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ytmp\t31032ers\user\downloads\.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ytmp\t31032ers\user\downloads\.exe Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\local settings\muicache\1b\52c64b7e::@c:\windows\system32\ndfapi.dll,-40001 Windows Network Diagnostics RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

"C:\Users\Qgksvqtf\AppData\Local\Temp\is-CSAG1.tmp\763a8296d62edd7b4a86528180dd61157a87fb87_0000685073.tmp" /SL5="$260176,268624,100352,c:\users\user\downloads\763a8296d62edd7b4a86528180dd61157a87fb87_0000685073"

Trending

Most Viewed

Loading...