PUP.Gamehack.GDA

Analysis Report

General information

Family Name: PUP.Gamehack.GDA
Packers: UPX
Signature status: No Signature

Known Samples

MD5: f94e136f88de70216d9dc1749c9b77fc
SHA1: 6c66b1947747f1ef1622c63210cca36ac1365923
SHA256: 8EE797DCD653868CEDB812FED271666691CF261642B73D3DD3EA4C11EFD3C657
File Size: 22.53 KB, 22528 bytes
MD5: 9f6901744d044ce7bc5df7eace6b18d4
SHA1: 62c78ab21f0067421af5e2762fa82c999dd1114d
SHA256: 2799B421F8FC354FF337530A7E1A158BFEF90A82BECC9A5D055095E56DF72255
File Size: 32.26 KB, 32256 bytes
MD5: bf3209a7a8a4ff233f825af46c6d687b
SHA1: 56a04000077cc4f522dd331241dcb16fca7b089c
SHA256: 6F8B778A8D06CDBE2B0A2BCB5D4A0BAAB980EF752517D6E03834CD6EDCE82F06
File Size: 53.76 KB, 53760 bytes
MD5: 8819741ed093c23bcb973d94702c0806
SHA1: 802becaf65de848355f6e77dc623f6fd5233bb76
SHA256: 5E19EACBA99C53576F7944C8AAA9A19CE883929A082DAD23052B721C40A460C2
File Size: 44.54 KB, 44544 bytes
MD5: d6d0524c5a6286ae1fcde919913aa67a
SHA1: 4e28445b14ce462683575d872fce6dcf61b585d0
SHA256: 77EC65DED9200A68DA3E8E7680D5FB881043AC41D37F90E0A977C3E9DB831F11
File Size: 43.01 KB, 43008 bytes
Show More
MD5: a2e361f9d612d798f2e4f810382344d2
SHA1: 711b10a64f34a9a8429891da53244bbaee650cee
SHA256: BBEF9E03EACB02108D2B578E8F29F70C5D6E993E2F543C64462B2816F78384B6
File Size: 109.06 KB, 109056 bytes
MD5: 00b3026ef14aacc928ed5b6421967b3b
SHA1: 84b8f9ff68e1662aa8a022bb7d0bfede232d2435
SHA256: D1CC0C51666888A9371A46EB938A3D484D25DCCE581E36FC26156476E3243FD1
File Size: 36.86 KB, 36864 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • No Version Info
  • packed
  • x86

Block Information

Total Blocks: 254
Potentially Malicious Blocks: 77
Whitelisted Blocks: 147
Unknown Blocks: 30

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 x x x x x x x x x x x x 0 x x x x x x x x 0 x 0 x x x x x x x 0 0 0 0 0 0 0 x 0 0 0 0 x 0 x x x x x x 0 0 x x x 0 0 x x x ? ? 0 0 ? x 0 0 0 0 0 0 ? 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x ? ? ? ? ? x x x x 0 0 0 0 0 x x x x x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 ? 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x ? x x 1 0 0 0 0 ? 0 0 x 0 x 0 0 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Gamehack.GDA
  • Stealer.FDC

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\directdraw\mostrecentapplication::name 84b8f9ff68e1662aa8a022bb7d0bfede232d2435_0000036864 RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\directdraw\mostrecentapplication::id ﹳ䩻 RegNtPreCreateKey
HKCU\software\microsoft\windows nt\currentversion\appcompatflags\layers::c:\users\user\downloads\84b8f9ff68e1662aa8a022bb7d0bfede232d2435_0000036864 DWM8And16BitMitigation RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Trending

Most Viewed

Loading...