PUP.GameHack.IA

Analysis Report

General information

Family Name: PUP.GameHack.IA
Packers: UPX
Signature status: No Signature

Known Samples

MD5: 1939f0a7ccd852fe883b07472a6c976a
SHA1: 31720fb19021487a5cf9b5c628111aa95fd4dbc6
SHA256: 3A86859FDBA2AAD44137DF2D6398FA37F997DA85AA532A38F879ABD04F40587B
File Size: 89.88 KB, 89878 bytes
MD5: b998c861aa836ac86689b75f9362bb8e
SHA1: 5a2ba1c3c6d78e08b4360d935e7dd743a1655252
SHA256: 82767C92273CF4D22E4CF19560A81D22B2FF3D372FC34EE9181A33CD4DE5F018
File Size: 94.21 KB, 94208 bytes
MD5: 4d18e4a6c0be886f0f3b00775f20693c
SHA1: ab178de5bfe522b6240ea7751f6e7cc084a112f1
SHA256: 561B71CFA3F5EE29AAFB377E5B78D96D0DB213FB6E634A35ED78D0A37716E961
File Size: 333.82 KB, 333824 bytes
MD5: a557a67b640ab41689ab9b9d2e901003
SHA1: 77e7fc3d6218ce082c59df6cfe15a93a3c1f0808
SHA256: D35387C564D7A573AC67FBEF060B4D3CD1759AD6D364CD1251B7E495A8E25A37
File Size: 333.82 KB, 333824 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • .UPX
  • 00 section
  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • packed
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 965
Potentially Malicious Blocks: 316
Whitelisted Blocks: 649
Unknown Blocks: 0

Visual Map

x x x x x 0 x x x x x 0 x x x x x 0 0 0 0 x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x 0 0 0 x x 0 0 0 x 0 0 x 0 0 0 0 0 x x 0 x x 0 x 0 0 0 0 x 0 x 0 0 0 0 0 0 x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 x 0 0 0 0 x 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 x 0 0 x x 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x x x x 0 0 x x 0 0 x x x x 0 0 x x x x 0 0 0 0 0 x x x 0 0 0 x x x 0 0 x 0 0 x 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x 0 0 0 0 0 0 0 x 0 x x x x 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 x x x 0 x 0 x x x 0 x x x x x x x 0 x x x x x x x x x 0 0 0 0 0 x x x 0 x 0 0 0 x 0 0 0 x 0 0 0 0 0 x 0 0 0 x 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x 0 x x 0 0 x 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • GameHack.IA

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Trending

Most Viewed

Loading...