Threat Database Hacktool PUP.GameHack.S

PUP.GameHack.S

Analysis Report

General information

Family Name: PUP.GameHack.S
Signature status: No Signature

Known Samples

MD5: 0a6764f0b75f6aae65fd77b90b0acff9
SHA1: 13b22d12db5ba602034c3360b24d59e12c3a7f5a
SHA256: 0B761ED0C9A4154453FD84DABD9DD3E93C0111518E1E948A523B62F9476C902D
File Size: 7.03 MB, 7033409 bytes
MD5: d39e6ffc9b0323ab4ec63caac0723e56
SHA1: c08969388157410c152e338b6f2fe97fbf247e41
SHA256: AA1BC388900A9A23A3270330F4A4D64DA3841FC41AA71F93AE70CE0687742D7F
File Size: 1.37 MB, 1374989 bytes
MD5: cd0eaa5fb8fbad53455e76c33c78947c
SHA1: 26009ac30d6ee32a5b6860fcfbc02c78a9183795
SHA256: 5619A417754AB56C18FBB4DD57D45EDAA2C6A86DF15B45A06CAB998457CDC2C6
File Size: 3.73 MB, 3727031 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Microsoft
  • MSFree
  • Oleg N. Scherbakov
File Description
  • 7z Setup SFX (x86)
  • W10 Digital Activation Program + KMS38
File Version
  • 1.6.0.2712
  • 1.00
Internal Name
  • 7ZSfxMod
  • Win
Legal Copyright Copyright © 2005-2012 Oleg N. Scherbakov
Original Filename
  • 7ZSfxMod_x86.exe
  • Win.exe
Private Build December 30, 2012
Product Name
  • 7-Zip SFX
  • Win
Product Version
  • 1.6.0.2712
  • 1.00

File Traits

  • big overlay
  • HighEntropy
  • Installer Version
  • x86

Block Information

Total Blocks: 607
Potentially Malicious Blocks: 26
Whitelisted Blocks: 581
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x 0 x x x x 0 x 0 0 0 0 0 x 0 0 0 0 x x x x x x 0 x x x x x x x x x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Banload.AS
  • Korplug.X
  • Kryptik.TZ
  • Trojan.Injector.Gen.FDD

Files Modified

File Attributes
c:\program files\common files\system\symsrv.dll Generic Write,Read Attributes

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx

Related Posts

Trending

Most Viewed

Loading...