PUP.Keygen.B

The detection of PUP.Keygen.B on your system indicates the presence of a potentially unwanted program (PUP) that may compromise your computer's security and performance. It is essential to understand the nature of this threat and take immediate action to remove it to prevent potential harm.

What Is PUP.Keygen.B?

PUP.Keygen.B is a type of potentially unwanted program that may be installed on your system without your knowledge or consent. It can be bundled with other software or downloaded from untrusted sources. PUPs like PUP.Keygen.B are often designed to generate revenue for their creators through various means, such as displaying advertisements, collecting user data, or redirecting users to suspicious websites.

How PUP.Keygen.B Operates

PUP.Keygen.B operates by exploiting vulnerabilities in your system or using social engineering tactics to trick you into installing it. Once installed, it can modify system settings, create unwanted registry entries, and install additional malware or PUPs. It may also communicate with its creators' servers to transmit user data or receive updates. PUP.Keygen.B can be challenging to detect and remove due to its ability to hide itself and disguise its activities as legitimate system processes.

Symptoms of Infection

Common symptoms of PUP.Keygen.B infection include unwanted advertise

Analysis Report

General information

Family Name: PUP.Keygen.B
Packers: PECompact v2.20
Signature status: No Signature

Known Samples

MD5: 2584d54c1eb5c64342cf2884c9262a2b
SHA1: 4e40dca8f76ac41473e96890353da3a964d78adc
SHA256: 93D0108385D1821B468E3DEB396D14B34D162EC5E212EF5291DC32340C90E4C8
File Size: 581.12 KB, 581120 bytes
MD5: 2950364edcbfe8de9e8d85894d097d37
SHA1: 192a3bd4627f134c14358d1042ed57f84e08b577
SHA256: AE82A6D1F2585C2EB9366CAAC839685686018CCAE4C93E4C7718CA58A1C51610
File Size: 697.86 KB, 697856 bytes
MD5: a99273626462f6cb3fa00386e40372b6
SHA1: cca26acf09f7a9072b722efd4fdfae17cca21e44
SHA256: CAA2035DCEA08D8F178F356CA468332FF459E49C0C16BE24990DE41937749147
File Size: 536.06 KB, 536064 bytes
MD5: fdba34d509d232834fd021854154253b
SHA1: 56dc36fe3c36ca3e2c85bcf8edc62a76c8c5b291
SHA256: 876CF35774BD9635895AA26639D79C6B8A72EAD4CAC28A324716E12AD65B913A
File Size: 120.83 KB, 120832 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • 00 section
  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • packed
  • PECompact v2.20
  • x86

Block Information

Total Blocks: 894
Potentially Malicious Blocks: 138
Whitelisted Blocks: 751
Unknown Blocks: 5

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 0 x 0 x x x x 0 0 x 0 x x x x x 0 x x x x 0 x x x x 0 x x 0 x x x x x x 0 ? x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 x 0 0 x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x 0 x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x 0 x x 0 x x x x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Related Posts

Trending

Most Viewed

Loading...