PUP.MSIL.Proxyware.A

Analysis Report

General information

Family Name: PUP.MSIL.Proxyware.A
Signature status: No Signature

Known Samples

MD5: 2bb4ae327b90144b0ebdf1ad67d8f630
SHA1: 0c8ed8ab30fb4fcdb4c85f16d98195a28d7b8b39
SHA256: 0AC22310CFCC993444D279729571CFC69CCF383F82784F1A5593E75B65A5DA9B
File Size: 522.24 KB, 522240 bytes
MD5: 3316c52a583e4e4a3558b9be8a28c5f2
SHA1: 6cb3edd5fb8857a9c30f3eadd62f382d187c7289
SHA256: 908C4B308076FC30213C744758DFEDD9AA9634893EB8A5B2F0FF612511D7A8F5
File Size: 522.75 KB, 522752 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.1.3.41
Company Name Microsoft Corporation
File Description Application Host Service
File Version 1.1.3.41
Internal Name AppHostService.exe
Original Filename AppHostService.exe
Product Name Microsoft Windows
Product Version 1.0.0+f779392360575e1bd8c43238934b6102605bd231

File Traits

  • .NET
  • Run
  • x86

Block Information

Total Blocks: 247
Potentially Malicious Blocks: 116
Whitelisted Blocks: 131
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 x 0 x 0 x x 0 x x 0 0 0 x 0 0 x x x x x x x 0 x x x x x 0 x 0 x 0 0 x x x x 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 0 x 0 x x x x 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x 0 x x 0 0 0 0 0 0 0 x x 0 x x x x 0 x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 x 0 0 0 x 0 x x 0 0 x x x x x 0 0 0 0 0 x 0 0 x x x x 0 0 0 0 0 0 0 x x x 0 0 x x x x x x x 0 0 0 0 x x x 0 x 0 x x x 0 x 0 0 0 0 x 0 x 0 x 0 x 0 0 x 0 x 0 x 0 x x x x 0 x 0 x 0 0 x 0 x 0 x 0 x 0 x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Proxyware.A

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
Show More
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation