PUP.Gamehack.GAIN
Table of Contents
Analysis Report
General information
| Family Name: | PUP.Gamehack.GAIN |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
709877f82bb6a4be01d5f75f87e14401
SHA1:
e68a21f9ce2f23de93d085b0c559d8e0b7389180
SHA256:
2ED4BAB3A1EDF0F59259AC266B549CE883AD547A9C0C40101542BF3ED3E2D175
File Size:
2.50 MB, 2497024 bytes
|
|
MD5:
019b6ad98918cfe839162fea5bafde6f
SHA1:
7cb67334fe05f78e6b467275a2a82a3ac2994828
SHA256:
9FF71033ABFD9160CCC123232A3E68510D1E1753EED19BE86A1435306203C1D2
File Size:
2.37 MB, 2365440 bytes
|
|
MD5:
34bf516de314b9d4f1b9813486548393
SHA1:
c5a05bbf7ba786ac44cf8b0b6fdbc925d29f37b0
SHA256:
2C391E863D9A7C1307D057DA9B87E7A704344AEC780FAFD9AB8227C6F1FA6D87
File Size:
3.42 MB, 3420160 bytes
|
|
MD5:
f4705b008f1c2461eee7ce926d6149f8
SHA1:
edd735acebb408b8901fb6a690e391d59513e701
SHA256:
3438CDF342DEF78C294DE3A7E9FA39EB2F0B6998713AEA410ADDDDB249769F2D
File Size:
2.49 MB, 2489856 bytes
|
|
MD5:
c09c92186eb50cc313b09eb821fe3a95
SHA1:
27ea3e0e1a91b521c4b4dc6dfda4411cb5844451
SHA256:
8E3E88CBCFBD0FF4BE869167DCAA1B384122DD90B1CD470DC3C7B66CABE0B802
File Size:
2.51 MB, 2506240 bytes
|
Show More
|
MD5:
93783505a4f5197ae445f8203f777bd3
SHA1:
ec4298b2a2f3a004d185b72f5c0f92c3b2368f57
SHA256:
AE93A0914DA3D596C4A2717DFD59E7133AD172C1CFE88C98ECB29AC3C2522A00
File Size:
2.46 MB, 2463232 bytes
|
|
MD5:
df1b85de047d6c1ab016f537bb6ed433
SHA1:
bbc9ea6b40cd00da8f162c78491ac07d0111c205
SHA256:
828D799341B8BEE6D457C029EE6996DE91985C8312862915492FFC198A059AA6
File Size:
2.50 MB, 2499584 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have exports table
- File doesn't have security information
- File has TLS information
- File is 64-bit executable
- File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
Show More
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.File Traits
- 2+ executable sections
- GetConsoleWindow
- HighEntropy
- imgui
- No Version Info
- ntdll
- VirtualQueryEx
- WriteProcessMemory
- x64
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 7,730 |
|---|---|
| Potentially Malicious Blocks: | 404 |
| Whitelisted Blocks: | 7,010 |
| Unknown Blocks: | 316 |
Visual Map
0
0
0
0
0
0
x
?
0
0
?
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
?
0
0
0
0
x
0
0
0
0
0
0
x
0
0
x
0
0
0
0
x
x
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
x
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
x
0
0
0
x
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
x
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
x
0
0
0
x
0
0
x
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
x
x
x
x
0
x
x
0
x
0
x
x
x
0
0
?
?
x
0
0
0
0
x
0
0
0
0
0
0
0
0
0
1
x
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
x
0
0
0
x
x
0
0
0
0
0
0
0
0
0
0
0
x
x
x
x
x
1
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
1
0
0
0
1
0
0
1
0
0
0
0
0
1
0
0
1
0
0
1
0
0
1
0
0
1
0
0
1
0
0
0
0
0
0
0
0
x
0
0
0
0
0
1
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
x
0
0
0
0
0
x
x
x
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
x
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
x
0
0
0
0
0
x
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
?
?
x
?
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
x
x
0
x
0
0
0
x
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
?
0
0
x
?
?
0
0
?
x
?
?
0
0
0
0
0
x
x
?
x
0
0
0
0
x
0
0
x
0
0
0
x
x
x
x
x
0
0
0
0
0
0
0
0
0
0
0
0
x
x
x
x
0
x
0
x
x
x
0
x
0
0
x
0
0
0
0
0
0
0
0
x
x
x
x
0
0
0
x
x
0
x
0
0
0
x
0
0
x
0
0
0
0
0
0
0
0
0
x
0
0
x
x
0
x
x
x
x
x
x
0
0
0
1
0
0
0
0
0
x
0
0
0
x
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
x
x
x
0
0
0
0
0
0
x
0
x
x
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
x
x
0
0
0
0
0
x
x
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
1
0
0
x
0
0
0
0
x
x
0
x
x
0
0
0
0
0
0
0
0
x
0
x
0
0
0
x
0
0
0
0
0
0
0
1
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
?
?
?
?
?
?
0
?
?
x
?
0
0
0
0
0
0
x
x
x
x
0
0
?
x
x
0
?
0
x
x
x
x
?
x
x
x
0
0
0
0
0
0
1
0
0
?
?
0
?
?
?
?
0
0
?
?
?
0
?
?
0
0
?
?
?
0
?
?
0
?
?
?
0
?
?
?
?
?
0
?
?
x
x
x
x
x
x
x
?
?
0
?
0
?
0
x
?
x
1
0
0
?
0
?
?
?
0
?
0
0
?
?
?
?
?
?
?
x
0
0
0
0
0
?
?
0
?
?
0
x
?
?
0
0
0
x
?
?
x
?
0
0
0
?
x
0
0
0
?
0
0
0
0
0
0
?
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
?
0
0
0
x
x
0
0
0
0
0
x
0
x
0
x
0
x
0
0
?
x
0
0
0
0
1
0
0
0
0
0
0
0
0
?
0
0
0
0
?
0
0
x
x
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
?
0
0
0
?
?
0
0
?
?
0
0
?
0
0
?
?
0
?
0
0
0
0
0
0
x
x
0
0
0
0
0
0
0
?
0
x
0
x
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
1
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
?
1
?
0
?
0
0
?
?
0
0
0
x
?
0
?
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
x
?
?
?
x
0
x
x
0
x
x
?
?
x
0
x
x
0
x
0
x
0
x
x
x
?
x
x
?
0
0
x
x
0
?
?
0
?
x
0
x
0
?
x
0
?
x
0
?
?
?
0
?
?
?
?
?
0
x
?
0
0
0
0
0
0
0
0
x
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
x
0
0
0
0
0
0
0
?
?
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
?
0
0
0
0
?
?
0
?
0
0
0
0
0
0
0
?
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
?
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
?
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
1
0
0
x
0
0
0
0
0
?
x
x
0
0
0
x
0
0
0
0
0
0
0
...
Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Gamehack.GAIN
- Gamehack.GSH
- Gamehack.GYF
- TelegramHack.G
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\namedpipe | Generic Read,Write Attributes |
| \device\namedpipe | Generic Write,Read Attributes |
| c:\guardianangel | Generic Read,Write Data,Write Attributes,Write extended,Delete,LEFT 262144 |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 퓊獚鞼ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 飻獟鞼ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | ો玳鞼ǜ | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
|
| Process Manipulation Evasion |
|
| Process Shell Execute |
|
| Anti Debug |
|
| User Data Access |
|
| Process Terminate |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
C:\Windows\System32\cmd.exe /c echo d | xcopy "c:\users\user\downloads" "C:\GuardianAngel\" /Y && attrib +s +h "C:\GuardianAngel" && "C:\Windows\System32\WindowsPowershell\v1.0\powershell.exe" -command "Add-MpPreference -ExclusionPath \"C:\GuardianAngel\""
|
C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /S /D /c" echo d "
|
C:\WINDOWS\system32\xcopy.exe xcopy "c:\users\user\downloads" "C:\GuardianAngel\" /Y
|
WriteConsole: Unknown error.
|
WriteConsole: Unable to create
|
Show More
WriteConsole: Angel
|
WriteConsole: 0 File(s) copied
|
C:\GuardianAngel\GuardianAngel.exe -r "c:\users\user\downloads"
|