Threat Database Hacktool Hacktool.GameHack.FD

Hacktool.GameHack.FD

By CagedTech in Hacktool

Threat Scorecard

Popularity Rank: 9,055
Threat Level: 50 % (Medium)
Infected Computers: 180
First Seen: September 13, 2021
Last Seen: March 20, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Hacktool.GameHack.FD
Signature status: No Signature

Known Samples

MD5: 60315567034223e5d2ccb740093bb38e
SHA1: afa250bd3db43c8aba5185fe1ef26dedd192f648
SHA256: F3870134D82C6D422C04BAC78E478B49B3A38A67DBF1A0A0A77E407E06C357DA
File Size: 2.68 MB, 2678784 bytes
MD5: 3ad92a4d2797cf2f1be94246c71df6f3
SHA1: 022a12e83b13c672f4dab79f95aa104b3262b282
SHA256: DDE00DBEF90D06BB8E264C2063626DEA786F53D9766D84CE7841AE67B402A0C5
File Size: 731.65 KB, 731648 bytes
MD5: 48f27f36e9a4df164cef136ae26fda98
SHA1: 899600490cb1308eb6ce9e88852ac09e0b9e943f
SHA256: B3A02B22EE986539462DCBED0591627A56014E35BCF43437724DA56B9D3AD9A5
File Size: 1.44 MB, 1444352 bytes
MD5: 7c2a3f30157ef2cb02f6917ae468dd53
SHA1: 639f0f8b3bf3b1475bd0996c2654dd883ccd6b91
SHA256: 20133BDFAEB0E0E2E5C5487894BCC3659D90F832F3930F4A61223112986A1F6C
File Size: 1.13 MB, 1125376 bytes
MD5: 38c800471aeb3413fb0c806c3f98c010
SHA1: 686b5612ae720ae413fa53203c53fcd7f8d6d1d4
SHA256: 20C7F3600FEDFFA54594BADF12510B396FD12A266CA0B2046D3DF60D80DBFF78
File Size: 1.46 MB, 1455616 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • 3DServers
  • MuEMU
  • UGK-SYSTEM
File Description
  • 3DGuard
  • MHPClient
  • UGK-SYSTEM
File Version
  • 2.0.0.0
  • 1.0.0.0
Internal Name
  • MHPClient
  • UGK-SYSTEM
Legal Copyright
  • 3DServers
  • Copyright © 2020
  • Copyright © MuEMU.pl 2015
  • MuEMU.pl © 2016
  • UGK-SYSTEM © 2024
Original Filename
  • 3DGuard.dll
  • Antihack.dll
  • MHPClient.dll
Product Name
  • MHPClient
  • MuEMU 3DGuard
  • MuEMU MHPClient
  • UGK-SYSTEM Antihack
Product Version
  • 2.0.0.0
  • 1.0.0.0

File Traits

  • dll
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 320
Potentially Malicious Blocks: 102
Whitelisted Blocks: 201
Unknown Blocks: 17

Visual Map

0 0 x x 0 x x x 0 ? x x 0 x 0 0 x x ? ? x 0 0 x 0 0 x x x x 0 x x 0 0 ? ? ? x x x x 0 x x ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x ? x x x x ? ? ? x 0 x 0 x x 0 x 0 0 x x x 0 x x x 0 0 x x x x x x 0 x x x 0 x x 0 0 x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x ? ? ? x x 0 x x x x x x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x 0 x x ? 0 0 0 x x x x 0 x x x x ? x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 1 1 0 0 0 0 0 1 1 2 3 1 0 1 0 0 2 2 0 2 1 1 0 x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.TJW
  • GameHack.FD

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\afa250bd3db43c8aba5185fe1ef26dedd192f648_0002678784.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\022a12e83b13c672f4dab79f95aa104b3262b282_0000731648.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\899600490cb1308eb6ce9e88852ac09e0b9e943f_0001444352.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\639f0f8b3bf3b1475bd0996c2654dd883ccd6b91_0001125376.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\686b5612ae720ae413fa53203c53fcd7f8d6d1d4_0001455616.,LiQMAxHB

Trending

Most Viewed

Loading...