Threat Database Cracks PUP.Crack.Y

PUP.Crack.Y

Analysis Report

General information

Family Name: PUP.Crack.Y
Signature status: No Signature

Known Samples

MD5: 908edddce80218bbe891c3cf2681fa23
SHA1: 8abd948079c77e6bd286f27ddc10f97142fb10ed
SHA256: FAF8E147DEA554A0EC90A03442E51D00D12BB264E02C22A0E0992B430EB9D441
File Size: 3.07 KB, 3072 bytes
MD5: e1031c8a271d02affd1b65bfaeaff44b
SHA1: 42776985b68395de66f7dd1a36c84053b758bff3
SHA256: FECAA31A7FBB19774430FF9C2AE1083417066A88F1FEBC016E27AA14FEA8D03B
File Size: 3.14 KB, 3136 bytes
MD5: 5ca2fda66a06c45f89f45ee644ab7ba5
SHA1: cefe9bb18e68c672bc73d8dd7abbce33e68f4527
SHA256: 38E29EB05CEF486951460348AF2D456CA5910501B107699C71B53F002797AD3B
File Size: 4.10 KB, 4096 bytes
MD5: 20ea924cd5b959cd2573187baff0a6d2
SHA1: 5d7881b2f35b7246aa8853b1b6dfb7d82a77930f
SHA256: E1FB24A46478764940ED07DEB315ACB6B2019114A7F4CCAAD55FF95331F657D5
File Size: 8.46 MB, 8457997 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • DT Soft Ltd.
  • Microsoft Corporation
File Description
  • Daemon Tools Pro Advanced v5.1.0.0333
  • GDIEXT Client DLL
File Version
  • 6.1.7600.16385 (win7_rtm.090713-1255)
  • 5.1.0.0333
Internal Name gdiext
Legal Copyright
  • © DT Soft Ltd.
  • В© Microsoft Corporation. All rights reserved.
Original Filename gdiext
Product Name
  • Daemon Tools Pro Advanced v5.1.0.0333
  • MicrosoftВ® WindowsВ® Operating System
Product Version 6.1.7600.16385

File Traits

  • dll
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nssa92d.tmp\aero.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nssa92d.tmp\en.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nssa92d.tmp\installoptions.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nssa92d.tmp\iospecial.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\nssa92d.tmp\iospecial.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nssa92d.tmp\modern-header.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nssa92d.tmp\modern-wizard.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nssa92d.tmp\ru.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nssa92d.tmp\ua.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsxa8af.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\8abd948079c77e6bd286f27ddc10f97142fb10ed_0000003072.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\42776985b68395de66f7dd1a36c84053b758bff3_0000003136.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\cefe9bb18e68c672bc73d8dd7abbce33e68f4527_0000004096.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...