Threat Database Hacktool PUP.GameHack.GAB

PUP.GameHack.GAB

The detection of PUP.GameHack.GAB on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.

What Is PUP.GameHack.GAB?

PUP.GameHack.GAB is a type of potentially unwanted program that is designed to compromise the security and performance of a computer system. The name suggests that it may be related to game hacking or cheating software, but its actual purpose and behavior may be more complex and potentially malicious. PUPs like PUP.GameHack.GAB can be installed on a system without the user's knowledge or consent, often through bundled software downloads or deceptive installation practices.

How PUP.GameHack.GAB Operates

Once installed, PUP.GameHack.GAB may operate in the background, consuming system resources and potentially collecting sensitive information about the user's browsing habits, personal data, or gaming activities. It may also attempt to connect to remote servers or download additional malware, further compromising the system's security. The exact behavior of PUP.GameHack.GAB can vary, but its presence on a system is a clear indication of a potential security risk.

Symptoms of Infection

Systems infected with PUP.GameHack.GAB may exhibit a range of symptoms, including slow performance, frequent crashes, and unusual network activity. Users may also notice unwanted pop-ups, ads, or browser redirects, as well as changes to their system settings or browser configurations. In some cases, the presence of PUP.GameHack.GAB may not be immediately apparent, making it essential to run regular system scans and monitor system activity for suspicious behavior.

How to Remove PUP.GameHack.GAB

  1. Boot your system in Safe Mode with Networking to prevent PUP.GameHack.GAB from loading and to allow for a more effective removal process.
  2. Run a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of PUP.GameHack.GAB and any associated malware.
  3. Uninstall any suspicious programs or software that may be related to PUP.GameHack.GAB, taking care to follow the uninstallation instructions carefully to avoid causing further damage.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any changes made by PUP.GameHack.GAB and to prevent further malicious activity.
  5. Reboot your system and run a follow-up scan to ensure that PUP.GameHack.GAB has been completely removed and that your system is secure.

Conclusion

The removal of PUP.GameHack.GAB is a critical step in protecting your system and personal data from potential harm. By following the steps outlined above and taking proactive measures to secure your system, you can help prevent future infections and maintain a safe and secure computing environment. Remember to always be cautious when downloading software, and to regularly scan your system for signs of malware to stay ahead of emerging threats like PUP.GameHack.GAB.

Analysis Report

General information

Family Name: PUP.GameHack.GAB
Packers: UPX x64
Signature status: No Signature

Known Samples

MD5: 1d46b8839c4f09b602ad2a3b8fa6f60f
SHA1: 34739cb6478c252613276424df6e9f3d57e36ebd
SHA256: 6C470D4D8E12D1A99039CADC9AEB9BC6D3F39D846244DA2C0EB1A5B1761774C8
File Size: 1.48 MB, 1481744 bytes
MD5: 6a097c3a3520f59027bf7f93564f3ba1
SHA1: 1815b771d7be6c851e6b8067e1de2dd68e17f80d
SHA256: CE9027875F77328F8BBC571AAEDBFF578217D17ABB61C9553983FB71648185C1
File Size: 247.81 KB, 247808 bytes
MD5: bea62784fcae5696e1610f7ae3300f9a
SHA1: a9a1e044cd40ba645ceb91b7980f5d4a0f7a19ec
SHA256: 87DD006B75A03240F7B2AFA51A37A5B5077993ACC8EE6F7BA60DDB41846DA1E6
File Size: 1.40 MB, 1401856 bytes
MD5: 7ab008aa3c6404084397dabc8c35a056
SHA1: 28a2d91a3eff0cab08833338c581dbdfbb09af7d
SHA256: CB0731CB940B4C9E4C06051716B0D466E2920FC39540C5F4BDA988809D1ACA88
File Size: 306.18 KB, 306176 bytes
MD5: fbaf9432402edb3afc20fa8a80619038
SHA1: fb38651c3959211260acf45ffa606c519a514d3c
SHA256: 9ACF0A21CEE7546E3F2555C028485A5B9BCAD98D5D7503B5C2C8B89DA86FC8EA
File Size: 314.90 KB, 314904 bytes
Show More
MD5: b5f1708e5cbe9d1e2103580d86d06021
SHA1: a398fb953bd1f847b313c239fd315f004a153b88
SHA256: 997D7C1FEC819B9DA5C30AE88956F1A4AB5D238E441BD664A52455B18FCE7BF1
File Size: 256.00 KB, 256000 bytes
MD5: ce815100ba00a11a38e33b87a0fb10fb
SHA1: 3f0ff60099654501a0bd8c6242a62c3db36cd9c1
SHA256: 9A038CBEF2E55ED789D55D0AA2D707FB1864D9F6DA07A79606972A901150F17B
File Size: 1.21 MB, 1211904 bytes
MD5: 233a839e2c788514be664fdb99f5065d
SHA1: 154d18dd0bec038578b9f05c600a85f3fdb30dd8
SHA256: CBB15D4BCC6FFE7706C21722B147A0B8A56250F38F61813AC686C5C04B50F292
File Size: 1.18 MB, 1184768 bytes
MD5: 516b8231eadf98bdfbad9603dbb0d779
SHA1: 0845880aced1548c0e4c1b015e4ba1fb32cb2565
SHA256: 5DDB2F3024749F5D1161134185E869F6BADA8477413E6C4775DEAD25247EDB7F
File Size: 399.36 KB, 399360 bytes
MD5: 1b350688ac0750e7dfbd38b2f1106375
SHA1: 09f57834afe101d4eab0ac35d0ab5e987dd07c60
SHA256: 8D9E07D2F6CCAF9A914ADF2FD4E7E5E2781ED5CDF0DC8A561B1C1B62F12892A3
File Size: 401.41 KB, 401408 bytes
MD5: 49a299a8df69904fe4d409dd17047f48
SHA1: a8768b2cf5cb449c2dcd48f3adf5431848b0704a
SHA256: 6B0444C2493849DE192067055595B7CEE78E7D642A7D2A0E5580F1BC4C67D2B5
File Size: 272.90 KB, 272896 bytes
MD5: e175b755c1339c7c164b6e6f9ef6ecda
SHA1: 7574fe81a6a85b8089400c5ffc1c07b3e679e3e6
SHA256: AC17EF9278D77FCE05DFEFE4801013993B52C6B24925DAF994B7D162E7C6EAC3
File Size: 3.72 MB, 3716608 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
Show More
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments http://www.autoitscript.com/autoit3/
Company Name
  • 3DMGAME
  • Cfx.re
  • NVIDIA
File Description
  • citizen-scripting-v8client for FiveM
  • Days Gone v1.0-v1.04 Plus 35 Trainer
  • DEATHLOOP v1.708-v1.772.0.36 Plus 13 Trainer
  • Dream Rivakes Plus 31 Trainer Updated 2022.07.30
  • MyBrowser By 熙然
  • NVIDIA Omniverse Carbonite SDK
  • The Legend of Heroes Trails of Cold Steel IV v1.0-v20211223 Plus 45 Trainer Updated
File Version
  • 3.8.49.0
  • 1.0.0.1896670335
  • 1.0.0.1
  • 1.0.0.0
Internal Name
  • citizen-scripting-v8client
  • Days Gone v1.0-v1.04 Plus 35 Trainer
  • DEATHLOOP v1.708-v1.772.0.36 Plus 13 Trainer
  • Dream Rivakes Plus 31 Trainer Updated 2022.07.30
  • The Legend of Heroes Trails of Cold Steel IV v1.0-v20211223 Plus 45 Trainer Updated
Legal Copyright
  • (C) 2015- CitizenFX Collective
  • Copyright (c) 2018-2023, NVIDIA Corporation
  • FLiNG Copyright (C) 2021
  • FLiNG Copyright (C) 2022
  • 熙然
Original Filename
  • citizen-scripting-v8client.dll
  • Days Gone v1.0-v1.04 Plus 35 Trainer.exe
  • DEATHLOOP v1.708-v1.772.0.36 Plus 13 Trainer.exe
  • Dream Rivakes Plus 31 Trainer Updated 2022.07.30.exe
  • The Legend of Heroes Trails of Cold Steel IV v1.0-v20211223 Plus 45 Trainer Updated.exe
Product Name
  • CitizenFX
  • Days Gone v1.0-v1.04 Plus 35 Trainer
  • DEATHLOOP v1.708-v1.772.0.36 Plus 13 Trainer
  • Dream Rivakes Plus 31 Trainer Updated 2022.07.30
  • NVIDIA Omniverse Carbonite SDK
  • The Legend of Heroes Trails of Cold Steel IV v1.0-v20211223 Plus 45 Trainer Updated
Product Version
  • 129.11+129.tc565.0f371ae5
  • 3.3.14.2
  • 1.0.994.1
  • 1.0.927.5
  • 1.0.884.5
  • 1.0.867.2
  • 1.0.0.1896670335
  • 1.0.0.1

Digital Signatures

Signer Root Status
NVIDIA Corporation DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Self Signed

File Traits

  • dll
  • imgui
  • packed
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 4,334
Potentially Malicious Blocks: 156
Whitelisted Blocks: 4,178
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 x x x 0 1 0 0 0 x 0 0 x 0 0 x 0 0 x 0 0 x 0 0 x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 0 x x 0 x 0 0 0 0 0 0 x x 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x x x x 0 x 0 0 x 0 x 0 x 0 0 0 0 x x 0 0 x x 0 0 x x 0 x 0 x x x 0 0 0 0 0 x x x 0 x 0 0 0 x x 0 x x 0 x x 0 x x 0 x 0 0 0 0 0 x x x 0 0 0 x x 0 x x 0 0 x x 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Autoit
  • Filecoder.DF
  • GameHack.G

Files Modified

File Attributes
\device\namedpipe\flingtrainernamedpipe_788 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\flingtrainer.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 摺猠䝍ǜ RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 *k�8��8tX��B�8 �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
Show More
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueryWnfStateNameInformation
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetSecurityObject
  • ntdll.dll!NtSetSystemInformation
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent

29 additional items are not displayed above.

Other Suspicious
  • AdjustTokenPrivileges
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Process Terminate
  • TerminateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider

Related Posts

Trending

Most Viewed

Loading...