PUP.Gamehack.JKGT

Analysis Report

General information

Family Name: PUP.Gamehack.JKGT
Signature status: No Signature

Known Samples

MD5: 119a5821b09542d621c886e02b77db25
SHA1: 83cfe36dfdf738dd9249dd30b31bf5dd4b58de0f
SHA256: 5FBB6F0592F0878D62D3F6C4F9BD9432B244465B1794F4E52040A2A5E10AE9A3
File Size: 27.65 KB, 27648 bytes
MD5: b8cf9f5ca150169c6abfcba37e5acd46
SHA1: 02ca6dc9e155aab574581e9e638455a765fc06db
SHA256: E04486CB0D99428E2FD62C3B2C7EB8AB3D5220434B8B9090952167D973C25298
File Size: 27.14 KB, 27136 bytes
MD5: 17a6ca47d926192d59d7f3c6a3bef52c
SHA1: 04fc3886eeaff155f60f21404c61e88260ec3fee
SHA256: 45F10CEC6B87E03109BE742886AE544914F3CA7C81C447D64C3DFF3A34FB095A
File Size: 3.34 MB, 3336704 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Comments PERIMUM UID BYPASS
Company Name PERIMUM UID BYPASS
File Description PERIMUM UID BYPASS
File Version 1.0.0.0
Internal Name INFINITY FREE UID BYPASS V 1.1.exe
Legal Copyright Copyright © 2025
Legal Trademarks PERIMUM UID BYPASS
Original Filename INFINITY FREE UID BYPASS V 1.1.exe
Product Name PERIMUM UID BYPASS
Product Version 1.0.0.0

File Traits

  • dll
  • imgui
  • ntdll
  • VirtualQueryEx
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 381
Potentially Malicious Blocks: 71
Whitelisted Blocks: 132
Unknown Blocks: 178

Visual Map

? 0 x ? ? ? ? ? ? 0 0 0 0 ? ? ? x ? x ? x ? ? x 0 0 0 x x 0 x 0 0 ? ? x ? x x 0 ? ? x x x x x ? x x x x x x x x x x ? x ? x ? x ? ? ? ? ? x ? x ? ? ? x x ? x 0 ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x x x ? ? 0 ? 0 ? ? 0 ? 0 0 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? x x x x ? x ? x ? x x ? x x ? x ? ? ? ? ? ? ? ? x x x ? x x ? ? ? 0 0 0 x 0 x x 0 x x 0 0 ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 ? ? ? ? ? x ? ? ? ? 0 ? ? ? x 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 x ? ? ? 0 ? ? ? ? 0 ? ? 0 0 0 0 0 0 ? 0 ? ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? ? ? 0 x x ? ? x ? ? ? ? ? x ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 ? ? x ? x x ? x 0 0 0 0 x ? ? 0 ? x 0 ? 0 0 0 ? 0 ? ? ? 0 ? 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiRestoreDC
  • win32u.dll!NtGdiSaveDC
  • win32u.dll!NtGdiSelectBitmap
  • win32u.dll!NtGdiSetDIBitsToDeviceInternal
  • win32u.dll!NtUserBuildHwndList
  • win32u.dll!NtUserCallTwoParam
  • win32u.dll!NtUserCreateEmptyCursorObject
  • win32u.dll!NtUserCreateWindowEx
  • win32u.dll!NtUserDestroyWindow
  • win32u.dll!NtUserFindExistingCursorIcon

28 additional items are not displayed above.

Keyboard Access
  • GetAsyncKeyState
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation

Trending

Most Viewed

Loading...