PUP.Linkury.F

Analysis Report

General information

Family Name: PUP.Linkury.F
Signature status: No Signature

Known Samples

MD5: 3de4d47efa14d25cf5a768e9f352e105
SHA1: 97866ad55c88327711bb5989d5422a3b4d690757
SHA256: A31EE98FA362D97DB7BAD0CA6FECD42CBFD38EEEF891E947014FCC06A9577B7E
File Size: 3.80 MB, 3797362 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • HighEntropy
  • No Version Info
  • x86

Files Modified

File Attributes
c:\users\user\appdata\roaming\__tmp_rar_sfx_access_check_9842515 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\agent.dat Generic Write,Read Attributes
c:\users\user\appdata\roaming\agent.dat Synchronize,Write Attributes
c:\users\user\appdata\roaming\config.xml Generic Write,Read Attributes
c:\users\user\appdata\roaming\config.xml Synchronize,Write Attributes
c:\users\user\appdata\roaming\ham.txt Generic Write,Read Attributes
c:\users\user\appdata\roaming\ham.txt Synchronize,Write Attributes
c:\users\user\appdata\roaming\main.dat Generic Write,Read Attributes
c:\users\user\appdata\roaming\main.dat Synchronize,Write Attributes
c:\users\user\appdata\roaming\md.xml Generic Write,Read Attributes
Show More
c:\users\user\appdata\roaming\md.xml Synchronize,Write Attributes
c:\users\user\appdata\roaming\moses.dat Generic Write,Read Attributes
c:\users\user\appdata\roaming\moses.dat Synchronize,Write Attributes
c:\users\user\appdata\roaming\moses.exe Generic Write,Read Attributes
c:\users\user\appdata\roaming\moses.exe Synchronize,Write Attributes
c:\users\user\appdata\roaming\shem.jpg Generic Write,Read Attributes
c:\users\user\appdata\roaming\shem.jpg Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey

Windows API Usage

Category API
Keyboard Access
  • GetKeyState
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • ShellExecuteEx
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent

Shell Command Execution

(NULL) C:\Users\Nxkbzpkx\AppData\Roaming\Moses.exe -f Moses.dat -l -a "c:\users\user\downloads\97866ad55c88327711bb5989d5422a3b4d690757_0003797362"