dup2patcher.dll

Classification: Malicious

dup2patcher.dll is a malicious file sample. Reported by 2 threat sources, last seen 2025-10-10. Detected by 39 antivirus engines.

Detection summary

  • 39 antivirus detections
  • 0 IDS alerts
  • 31 processes observed
  • 0 contacted hosts
  • 0 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Cyber Threat Alliance 2025-10-10 15:14:13 2025-10-10 15:14:13
Generic Malware Hybrid-Analysis 2025-07-14 10:15:03 2025-07-14 11:45:10

Sample information

Filenames
dup2patcher.dll
File type
PE32 executable (DLL) (GUI) Intel 80386, for MS Wi ...
Size
73728 bytes
MD5
76086eeb401cf8f4b2293bb5343c4f7e
SHA-1
57a706501f714aacda8c9832690830a661eb9874
SHA-256
eb9ee7189e4cdff6ac854baa78117f04937e944774f393952c20e5e963340347
First indexed
2025-07-14 10:09:37
Last updated
2026-09-03 00:34:34

Antivirus detections

EngineDetection
AhnLab-V3HackTool/Win32.Patcher.R207239
Antiy-AVLHackTool/Win32.Patcher
CAT-QuickHealTrojan.Ghanarava.17474312543c4f7e
CTXdll.trojan.patcher
ClamAVWin.Dropper.Genericrxem-9937527-0
CylanceUnsafe
CynetMalicious (score: 100)
DeepInstinctMALICIOUS
ESET-NOD32Win32/HackTool.Patcher.T potentially unsafe
Elasticmalicious (high confidence)
FortinetRiskware/Patcher
GDataWin32.Trojan.PSE.1GI7FPD
GoogleDetected
IkarusPUA.HackTool.Patcher
JiangminTrojan.Generic.fonq
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
LionicHacktool.Win32.Patcher.3!c
MalwarebytesGeneric.Malware.AI.DDS
MaxSecureTrojan.Malware.3405.susgen
McAfeeDReal Protect-LS!76086EEB401C
MicrosoftHackTool:Win32/Keygen
Rising[email protected] (RDML:Kvm2UILx2kkWLLpRCXO4Ww)
SUPERAntiSpywareHack.Tool/Gen-Patcher
SangforTrojan.Win32.Save.a
SentinelOneStatic AI - Suspicious PE
SkyhighBehavesLike.Win32.Generic.lm
SophosGeneric Patcher (PUA)
SymantecSMG.Heur!gen
TrellixENSGenericRXEM-OL!76086EEB401C
TrendMicroTROJ_GEN.R002C0OD425
TrendMicro-HouseCallTrojan.Win32.VSX.PE04C9f
VaristW32/Agent.JOS.gen!Eldorado
WebrootW32.Trojan.Gen
YandexTrojan.GenAsa!30XG1D/2cC8
alibabacloudHackTool:Win/Patcher.T
CrowdStrikewin/grayware_confidence_100% (W)
Kingsoftmalware.kb.a.941
LionicTrojan.Win32.Patcher.4!c

Process list

NameCommand line
<Ignored Process>
rundll32.exe"C:\dup2patcher.dll",#1
WerFault.exe-u -p 412 -s 600
WerFault.exe-u -p 412 -s 600
WerFault.exe-u -p 412 -s 600
rundll32.exe"C:\dup2patcher.dll",#2
rundll32.exe"C:\dup2patcher.dll",#4
rundll32.exe"C:\dup2patcher.dll",#3
WerFault.exe-pss -s 460 -p 412 -ip 412
rundll32.exe"C:\dup2patcher.dll",#5
WerFault.exe-u -p 9108 -s 608
WerFault.exe-u -p 9108 -s 608
WerFault.exe-u -p 9108 -s 608
rundll32.exe"C:\dup2patcher.dll",#6
rundll32.exe"C:\dup2patcher.dll",#7
WerFault.exe-pss -s 552 -p 9108 -ip 9108
rundll32.exe"C:\dup2patcher.dll",#8
WerFault.exe-u -p 8868 -s 608
WerFault.exe-u -p 8868 -s 608
WerFault.exe-u -p 8868 -s 608
rundll32.exe"C:\dup2patcher.dll",#9
WerFault.exe-pss -s 592 -p 8868 -ip 8868
rundll32.exe"C:\dup2patcher.dll",#10
rundll32.exe"C:\dup2patcher.dll",#11
rundll32.exe"C:\dup2patcher.dll",#12
rundll32.exe"C:\dup2patcher.dll",#13
rundll32.exe"C:\dup2patcher.dll",#14
WerFault.exe-u -p 6252 -s 600
WerFault.exe-u -p 6252 -s 600
WerFault.exe-u -p 6252 -s 600