PUP.GameHack.FF

Analysis Report

General information

Family Name: PUP.GameHack.FF
Signature status: No Signature

Known Samples

MD5: 432a537c7dc8f4bb2a351eb9671a4c71
SHA1: b11d9fd7cc7e24f800959d050a1c3e8e77651e1e
SHA256: BE84E4F73399BFB15B4CEAA217C05C73D51BFD4DDE12963382822679EF543318
File Size: 195.07 KB, 195072 bytes
MD5: bee0c6831aa84891daf3acfa36bfdcf6
SHA1: c1ffc156bfcf2fa6e18fa0499427452e2f9fb2e1
SHA256: 01F19436C08E6F52A5DB66C1E26941229CEADF0795E2F9DADA4768F247896D7D
File Size: 204.80 KB, 204800 bytes
MD5: 8b1872c8bfd1a15cf327403c63c3a947
SHA1: 3046a6df3564d08313124ca457d7c994be6e4551
SHA256: 1DC88734D669AECECC1D85659DBB253F1D4245CB323F8D34575A003760221275
File Size: 36.35 KB, 36352 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Point Blank
File Description Point Blank
File Version 1.0.0.1
Internal Name PointBlank.exe
Legal Copyright © Point Blank . All right reserved.
Original Filename PointBlank.exe
Private Build Built
Product Name Point Blank®® Application
Product Version 1.0.0.1

File Traits

  • GetConsoleWindow
  • HighEntropy
  • No Version Info
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 114
Potentially Malicious Blocks: 25
Whitelisted Blocks: 89
Unknown Blocks: 0

Visual Map

0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x x 0 0 x x x x 0 x x x x x 0 0 2 2 0 0 1 1 0 0 1 1 1 0 1 2 3 1 0 0 0 2 2 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • GameHack.FF

Windows API Usage

Category API
Network Info Queried
  • GetAdaptersInfo
Network Wininet
  • HttpOpenRequest
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
  • InternetReadFile
Anti Debug
  • NtQuerySystemInformation
Network Winhttp
  • WinHttpOpen

Related Posts

Trending

Most Viewed

Loading...