Threat Database Hacktool Hacktool.CsgoInjector.GG

Hacktool.CsgoInjector.GG

By CagedTech in Hacktool

Threat Scorecard

Popularity Rank: 6,687
Threat Level: 50 % (Medium)
Infected Computers: 86
First Seen: June 26, 2024
Last Seen: July 19, 2026
OS(es) Affected: Windows

A malware detection has been made for Hacktool.CsgoInjector.GG, a type of malicious software designed to compromise computer systems. This report provides an overview of the threat, its operational methods, symptoms of infection, and steps to remove it from an affected system.

What Is Hacktool.CsgoInjector.GG?

Hacktool.CsgoInjector.GG is identified as a hacktool, which is a category of malicious software used for unauthorized access or control of computer systems. The name suggests it may be related to cheating or exploiting vulnerabilities in online games, particularly those like Counter-Strike: Global Offensive (CS:GO), but without specific details, it's crucial to understand the general risks associated with hacktools. They can be used to bypass security measures, steal sensitive information, or disrupt system operations.

How Hacktool.CsgoInjector.GG Operates

The exact operational details of Hacktool.CsgoInjector.GG are not specified, but generally, hacktools operate by exploiting vulnerabilities in software or manipulating system settings to achieve their malicious goals. They can be distributed through various means, including downloads from untrusted sources, email attachments, or infected software packages. Once installed, they can run in the background, hidden from the user, and perform their intended malicious functions, which could range from data theft to allowing unauthorized access to the system.

Symptoms of Infection

Symptoms of an infection can vary widely but may include unusual system behavior, such as unexpected crashes, slow performance, or the appearance of unwanted programs or toolbars. Users might also notice that their gaming performance is unusually enhanced or that they are accessing features that should not be available to them. In some cases, the infection might not display obvious symptoms, making it difficult for users to detect without the aid of security software.

How to Remove Hacktool.CsgoInjector.GG

  1. Boot your computer in Safe Mode with Networking to limit the malware's ability to run and interfere with the removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove the malware.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time the malware was detected.
  4. Reset your web browsers, such as Chrome, Firefox, or Edge, to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. After completing the above steps, reboot your computer and then perform another scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

The detection and removal of Hacktool.CsgoInjector.GG are critical steps in protecting your computer system from potential harm. By understanding what this malware is, how it operates, and following the removal steps outlined, you can help ensure your system's security and integrity. It's also essential to practice safe computing habits, such as avoiding downloads from untrusted sources and regularly scanning your system for malware, to prevent future infections.

Analysis Report

General information

Family Name: Hacktool.CsgoInjector.GG
Signature status: No Signature

Known Samples

MD5: 0d66fa7f3838cd4c063bbce09c66c358
SHA1: 455c94978acd06bf2de93224373d3b603e38d955
SHA256: 2ED4FA893F6D0088B2CBF86BCBAEA13F4E80DD6A99C5D7BA06A6CCEC370DCC9F
File Size: 1.20 MB, 1195008 bytes
MD5: b74c2639c870279bbe85593c7da129ae
SHA1: 9f6059534568f0cc0ffa95182df6335f9daaf5a3
SHA256: BE9D5A68103E3D29902096D9503781CB64394B54DA001F4F6EC0C615257DBA3A
File Size: 5.51 MB, 5512192 bytes
MD5: 4da6d4213a6dea229ed639952f543bd3
SHA1: 2b13efec645e7baa03f139159143cd8cb22b85af
SHA256: 2824BB1F5F64506CEE01999CEE473E5815C336A4B79B7481E0CCC9658CB031EC
File Size: 1.21 MB, 1213952 bytes
MD5: 1c813dd42ff6d49f086229a8fc30134f
SHA1: 19cba72bb3de12e02138790134cedb1f41428db0
SHA256: E5ED16044B8A54D7DE27544CD9E1D0F081D9BF8ADF37E1712EAC58EC387DDE1A
File Size: 2.22 MB, 2224640 bytes
MD5: 9aaf7c36852ca57a55403e97dae399fa
SHA1: 7ad5730dd8ec3edbf0738f20f8e5cdad9b1bb16b
SHA256: A65DF991880527860B42563F457839BFBC67F4F5A14D14585BD029BCB07CFC3B
File Size: 1.09 MB, 1088512 bytes
Show More
MD5: b0b65c75d0f0b571fd5270c6b0479077
SHA1: e3efdc891f3fc13f23fa15f6303c97cecbca949e
SHA256: 5998D5A09A0B334767623A369FB3839CB150326D83156EEC6DAF95C0D9C0E2F7
File Size: 1.22 MB, 1222144 bytes
MD5: 02e599b88ecb1b94759e06a52e0eba5f
SHA1: 60e8af0576e2dd47cca8510782a5d189ae249057
SHA256: 713ECE01541695F58F028C14609C8E7381DE4D5F0E126683346331F37E4F5C31
File Size: 1.71 MB, 1710080 bytes
MD5: 9a7208094bc42241f1c1b530fe105a73
SHA1: 458d4d3281c0539758e33f3498b3d696993676ee
SHA256: 61320FB147ED7A1E71F96751315981406F67DD3190BA2EA7F89F5DF0F7A105B7
File Size: 1.22 MB, 1219072 bytes
MD5: 950ec1355efa0e80dc7511c4735f1643
SHA1: aeb63a67530396e6af7963048a43f495336f253e
SHA256: C2941FBD2BA96309DB6D786A7432D76D18E898F7E2F10C283859EA1BBC9C71E0
File Size: 2.62 MB, 2624000 bytes
MD5: 93c50c70feb7c88b6d393e58fc0ca0a4
SHA1: b088cd11c1095a9a0b0b610c552db921fe05a2e7
SHA256: CDAB038568232B446704B47CC829202B97210D9878F56BE099C51E07965923D1
File Size: 1.11 MB, 1107456 bytes
MD5: a65a2592aeef2d645a514b7707d8ba7b
SHA1: fa6dc651860fb9860680b0b921c8480438e8c061
SHA256: DA524BD80745A228667B0BF7E81744A1C57DD3E897FB98AA3A4490A51ADDF50C
File Size: 1.11 MB, 1107456 bytes
MD5: 801118afab6c330c7caac76f6b283cd3
SHA1: 95ce8e10d416b74300e40bed35c67ca003d6b412
SHA256: 3C2207F1740B2D564768DF98B755F95A45902B8954D84A5A2CC2D37D290E4C60
File Size: 2.30 MB, 2298368 bytes
MD5: ab36524846492954cb7769541d04d842
SHA1: ae3d9557721ea0329ff5353ee8d1a52dd279b00d
SHA256: 0CC82D2B585A037BC65410B81F9FC973E9D78C0E62D0B48FE10F26E25356DFA1
File Size: 1.21 MB, 1210880 bytes
MD5: 07cfe923c648a6d98a3f90996230ad10
SHA1: 73e9cd8b357f1efc56b48ac34f739b94b16918ee
SHA256: CD21EDA0C31BD3444BA3E03A6F064C2A0497C267E40896049B3A8E3D1412AF51
File Size: 1.30 MB, 1295872 bytes
MD5: c282795d27ab63b9855464eecf821042
SHA1: 846a17584a4d0adf84ad311971501ec2d9f1a891
SHA256: 1EEAF1574EC9B4D02D8A0363E62F401B01428D69399402CC88AB60B4D243648A
File Size: 1.28 MB, 1281024 bytes
MD5: a7ca9a9f9f9c9def2e84a7d5f5734037
SHA1: 015bc6e163abdefe5fa9ddb438eb7e643ba9a756
SHA256: 4C7CBD71DE6AD8C68E86888FEEC4A604FFAAFA7EBB821F7944F11BB44DFDF6BB
File Size: 9.03 MB, 9034240 bytes
MD5: a5d4a8ceabb991c61207d798c503b76e
SHA1: fe4a043a4fd83914836c143e35150df406d8f187
SHA256: 0718ACC807D195D0BA1F35272B8FB333488DE8F5D406C4E0CA9F62524F2AAFED
File Size: 1.21 MB, 1206272 bytes
MD5: 362f50bc1fd371d7d6e9188069a4825c
SHA1: 1086a0298781458072514889c8973ea82b0f82b8
SHA256: 6551A17CB5C8378905FFF56BE7D913C739771BAC675B3C4F8AB42D1E8B217792
File Size: 1.22 MB, 1219584 bytes
MD5: d0705985bcb4786954e0aa2c724c003a
SHA1: 0c205b262c88caed7df9414760b6ecc55deca17b
SHA256: 1AB7A4C6E4048BDBBD47C01E35FA2BC13B88A5EE84F688E60FFB6A355F44DCCC
File Size: 1.36 MB, 1364992 bytes
MD5: 97f9cb9c0e8cd492e2d5bf977c0489f5
SHA1: f859cb87add55dbd522f5eb6985db66e19f500d7
SHA256: 4BEC3F91634AB09928C584140298DF9219BB03682962C709CD8AE601704F25C0
File Size: 1.11 MB, 1106944 bytes
MD5: db8cc94044d8a2910e9a1f4ee31754cb
SHA1: 951eefcd7d735f18a2860040c8b1f733c2398b19
SHA256: B16DF228661824DAE718E5131E3CA36E620ED4A9BBAFECA5E9E9D3D690C528B7
File Size: 749.06 KB, 749056 bytes
MD5: 8a5e0fc491a7efba6dbbc0120ce8a88b
SHA1: 14335f62948f87b274582019d61d120a790a171f
SHA256: 42823466FEAF160AB39F56263D7FE14B191452AC98FD43E678F893BBC4AFB01E
File Size: 7.23 MB, 7225856 bytes
MD5: 71c0ebcfbdec1b7bbae82835ec902568
SHA1: 00b1c1837aebee385b5b32c7dd0917c1f97f8169
SHA256: 0EBAEB3C49337EBFA515B0D6180A24BB6AA078BAAA585A7268ECFF102C77BF37
File Size: 1.11 MB, 1107968 bytes
MD5: 9c308aa12e19592f1f48e7e3631cafa0
SHA1: f23bad762555a7fb16d912799e05bff9818ee033
SHA256: 2A930B249256D2E6FD5BCC1AFF4B19F0EF3F53E47D08D53F70CB36BDCA43B4D8
File Size: 764.93 KB, 764928 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is .NET application
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Company Name
  • Elysium
  • Tsuda Kageyu
File Description
  • Elysium Loader
  • MinHook - The Minimalistic API Hook Library for x64/x86
  • runtimebroker
File Version
  • 1.3.3.0
  • 1.0.0.0
Internal Name
  • Elysium Loader
  • MinHookD
  • NAFTAL X KATKOT.exe
Legal Copyright
  • Copyright (C) 2009-2017 Tsuda Kageyu. All rights reserved.
  • Copyright © 2025
Legal Trademarks Tsuda Kageyu
Original Filename
  • Elysium Software.exe
  • NAFTAL X KATKOT.exe
Product Name
  • Elysium Loader
  • MinHook DLL
  • runtimebroker
Product Version
  • 1.3.3.0
  • 1.0.0.0

File Traits

  • dll
  • GetConsoleWindow
  • HighEntropy
  • imgui
  • No Version Info
  • ntdll
  • VirtualQueryEx
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 148
Potentially Malicious Blocks: 12
Whitelisted Blocks: 133
Unknown Blocks: 3

Visual Map

0 0 0 0 0 0 ? 0 0 0 0 ? 0 x 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 x x 1 x 0 0 0 x x 0 0 0 0 0 x x 0 x 0 1 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 1 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • CsgoInjector.GG
  • Gamehack.DSE
  • Gamehack.EBB
  • Kryptik.DTE
  • MSIL.DllInject.GDK
Show More
  • Trojan.Agent.Gen.AMQ

Files Modified

File Attributes
\device\namedpipe\internalp Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAllocateReserveObject
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
Show More
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletionEx
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetIoCompletionEx
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair

113 additional items are not displayed above.

Process Shell Execute
  • CreateProcess
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation

Shell Command Execution

schtasks /delete /tn "Microsoft\Windows\Update\WindowsUpdate" /f
schtasks /delete /tn "Microsoft\Windows\DiskCleanup\SilentCleanup" /f
schtasks /delete /tn "Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser" /f
schtasks /delete /tn "ElysiumCheatsCleanup" /f 2>nul
schtasks /query /tn "ElysiumCheatsCleanup" 2>nul

Related Posts

Trending

Most Viewed

Loading...