PUP.Blat.A

Analysis Report

General information

Family Name: PUP.Blat.A
Signature status: No Signature

Known Samples

MD5: 09be9b392e777dfcdd8a3777376ab531
SHA1: 3578dbe921966c3cf41dc7c11220ffaa14f95b93
SHA256: C8A81C7EA43421ABE8CA80BCFEB1D2A06F792DAD10BC0E34E5A9D67E17592154
File Size: 4.81 MB, 4813012 bytes
MD5: 9cd9afb61e3f57ab66e803e7e618b9e8
SHA1: 1f170baba68fd659063821315907bdb6dfe1463a
SHA256: D8DA1F1217EA8B11BD1936624B1605A818B10B3DDE52ADE65C94CDFC60869436
File Size: 115.20 KB, 115200 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments Authors and contributors include P.Mendes, M.Neal, G.Vollant, T.Charron, T.Musson, H.Pesonen, A.Donchey, C.Hyde
Company Name http://www.blat.net/
File Description A Win32 command line eMail tool
File Version 2.6.2
Internal Name blat
Legal Copyright No copyright at all
Original Filename blat.exe
Product Name
  • Blat
  • Task Monitor
Product Version
  • 2.6.2
  • 1.1

File Traits

  • x86

Block Information

Total Blocks: 183
Potentially Malicious Blocks: 131
Whitelisted Blocks: 52
Unknown Blocks: 0

Visual Map

0 x 0 0 x x x x 0 0 0 0 0 0 x 0 x 0 0 x x 0 x x x x x x x x x 0 0 x x x x 1 x x x x x x x x x 0 x x x x x x x 0 x x x x 0 x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x 0 x x 0 x x x 0 0 x x 0 x x x x x 0 x x 0 0 x x x x x x x x x x x 0 x x x x x x 0 0 x 0 0 x 0 0 x x 0 0 x x 0 0 x x x x x x x x x 0 0 0 0 0 0 x x x x x x x x x x 0 x x x x x x 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Blat.A
  • Blat.B

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nssa8de.tmp\installoptions.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nssa8de.tmp\iospecial.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\nssa8de.tmp\iospecial.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nssa8de.tmp\modern-wizard.bmp Generic Write,Read Attributes

Windows API Usage

Category API
Process Manipulation Evasion
  • ReadProcessMemory
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Related Posts

Trending

Most Viewed

Loading...