PUP.GameHack.LE

Analysis Report

General information

Family Name: PUP.GameHack.LE
Signature status: No Signature

Known Samples

MD5: 3f34107a14a2cef1704f9b180d660086
SHA1: 907b260a49ed403e3fb2ba2832c7bc759d4ce90f
File Size: 1.64 MB, 1643712 bytes
MD5: f1eb1be4f4450da7ee02f806b7e1d6b7
SHA1: f6a34d08a01fd24c36b388b59c4094eea88e0051
SHA256: 19CD2A43F324ADFE2CE82695C50A862749F1621C19EF2BDA2ACCBB54F3CD7C67
File Size: 6.46 MB, 6457024 bytes
MD5: d01ed1f4da33ecc52bdb6cc16b701de5
SHA1: e2cb04a62eb0d7c52c8155768f9fc74dea2c2b75
SHA256: 88239FD25BF725BFE644CA7A7D0EC5EC466AA5FD6640630BA62F966D5E2A2611
File Size: 2.02 MB, 2023616 bytes
MD5: f9a87d8968eb18c237c4cde96ada87c9
SHA1: 3b1ffa00b6a32f13202f0330a7a338d524bf09f3
SHA256: FE971285DF7190D2F526F668EA8F66E14C429F888894F87CEA1246B498B31304
File Size: 6.58 MB, 6579904 bytes
MD5: 514b8d80ff13888f0cc51fef114f417c
SHA1: 2106ce8a0c6d93e5db18bac7b8d1297933eac4e4
SHA256: 9C80AE2AB14A7BEDF5DB95CC2F88FE3883BE2864FE6FBB120740C31CC1A4A8CD
File Size: 1.40 MB, 1400000 bytes
Show More
MD5: 612f891da1090f9f2c90a92bbc02b9d6
SHA1: 22714ec746626532116cbf9f6a15990fdba0a54e
SHA256: 05DA973FAA3017B91F4A47E7D56B7F0506B6325A84CBB9AE5CF7CD5D1A36ECEF
File Size: 2.16 MB, 2161344 bytes
MD5: df22613289098ff3dd4c882043451f03
SHA1: 0190908e344f48a8c3e7b2a4e5c7d1c3779dda89
SHA256: 493B5885542C96538BF6911DF3D010E819DA48EE35EBD1772ED831C7CA2954BD
File Size: 6.42 MB, 6422208 bytes
MD5: 520e4a5ed778b0b6751544ea4408e36f
SHA1: 8b4ae197fca7814fc44189f13590d9666705c680
SHA256: C050837DF1EA0F429AE7E4C919D58394C436C541AD8C56B7C3A64E799354C413
File Size: 1.82 MB, 1820352 bytes
MD5: 385d3f9bd48a3c36370ab5847d6e4fcc
SHA1: 574fa59ed581439849ad2825a7e96cbe8cc0a130
SHA256: F645666B0E57616387F950E86522C18BA2DAC87A0096890AEE04187AA3ECAF09
File Size: 1.65 MB, 1646272 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 725
Potentially Malicious Blocks: 10
Whitelisted Blocks: 715
Unknown Blocks: 0

Visual Map

x x x 0 0 x 0 x x 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • GameHack.L

Files Modified

File Attributes
c:\users\user\cheathappens\work\cheathappens.net Synchronize,Write Attributes
c:\users\user\cheathappens\work\inetcheck.dat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\cheathappens\work\inetcheck.dat Synchronize,Write Attributes
c:\users\user\cheathappens\work\runtime\cheathappens.net Synchronize,Write Attributes
c:\users\user\cheathappens\work\runtime\inetcheck.dat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\cheathappens\work\runtime\inetcheck.dat Synchronize,Write Attributes

Windows API Usage

Category API
Network Winsock2
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • connect
  • freeaddrinfo
  • getaddrinfo
  • gethostbyname
  • getpeername
  • getsockname
  • inet_addr
  • send
  • socket

Trending

Most Viewed

Loading...