PUP.Gamehack.LOA

PUP.Gamehack.LOA is a detection name used to identify a potentially unwanted program (PUP) that is associated with game hacking or cheating tools. Programs flagged under this detection are typically bundled with or disguised as game modification utilities, cheat engines, trainers, or "boosters" that promise to give players an unfair advantage in video games, such as unlimited in-game currency, unlocked features, aim assistance, or other altered gameplay mechanics. While these tools may appear appealing to gamers looking for shortcuts, they often carry hidden risks that outweigh any perceived benefit.

What PUP.Gamehack.LOA Does

Like most programs in the potentially unwanted category, PUP.Gamehack.LOA is not necessarily classified as outright malware, but it exhibits behaviors that can compromise a user's privacy, system stability, or overall computing experience. Typical behavior for this type of detection includes altering game files or memory processes to enable cheats, injecting code into running applications, and modifying system settings to bypass anti-cheat protections. In many cases, such tools also install additional software components without clear disclosure, run background processes that consume system resources, and may attempt to disable or interfere with security software to avoid detection while the hack tool operates.

How It Usually Gets Onto Computers

Programs like PUP.Gamehack.LOA are commonly downloaded by users themselves from third-party websites, forums, or file-sharing platforms that host game cheats, mods, or cracked software. They are frequently bundled with other free downloads, disguised as legitimate patches, or distributed through deceptive advertising that promises game-enhancing features. Because these tools often originate from unofficial or unverified sources, they can also be repackaged with additional unwanted components that the user never intended to install.

Risks for the User

Installing game hack tools carries several risks. Many online games actively detect the use of cheat software, which can result in permanent account bans or loss of progress. Beyond the gaming risk, these tools often require disabling security features or granting elevated system permissions, which can expose the computer to additional threats. Some game hack utilities have been known to secretly collect personal information, display intrusive advertisements, or serve as a gateway for more harmful software to be installed later. Because the source of these programs is typically unofficial, there is no guarantee of the safety or integrity of the code being run on the system.

Signs of Infection

Users affected by PUP.Gamehack.LOA-type software may notice unusual slowdowns in system or game performance, unexpected pop-up advertisements, changes to browser or system settings without permission, and the appearance of unfamiliar processes running in the background. Security tools may also flag the presence of unrecognized files, alert the user to blocked or quarantined items, or report suspicious network activity as the program attempts to communicate with external servers.

How to Stay Protected

To avoid these types of potentially unwanted programs, users should only download software from official game platforms or trusted developers, and avoid third-party cheat tools, cracked games, or unofficial modifications altogether. Reading installation prompts carefully and declining bundled offers during setup can also help prevent unwanted software from being installed. Keeping security software up to date and performing regular system scans can help detect and remove such programs before they cause harm. Ultimately, the safest way to protect a computer and gaming accounts is to avoid game hacking tools entirely, since the risks to both security and gameplay integrity generally outweigh any temporary advantage they may offer.

Analysis Report

General information

Family Name: PUP.Gamehack.LOA
Signature status: No Signature

Known Samples

MD5: 577d0017d59456324d121c8622477e0b
SHA1: eb8e374b682e2d1be57fea889aea0c2b319b33a3
SHA256: 279042EE3EF13E3B01AEE0A421F1928AF1EF8B39FAAE637F6D0AFF308FA3BA62
File Size: 2.93 MB, 2932736 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • fptable
  • imgui
  • x64

Block Information

Total Blocks: 4,670
Potentially Malicious Blocks: 825
Whitelisted Blocks: 3,843
Unknown Blocks: 2

Visual Map

x x 0 x 0 0 0 x x x x x x x x 0 0 0 x 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x x x 0 0 x 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 0 0 0 0 0 x 0 1 0 0 0 x x 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 x 0 x x x x x 0 x 1 x 0 x x x x x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 x x x 0 0 x x 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 1 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 x 0 x 0 x x 0 0 0 0 0 0 x x 0 0 0 x x x x x x 0 x x 0 0 x x x x 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x x x 0 0 0 x 0 x 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 x 0 0 x x 0 0 x x 0 x 0 0 0 0 0 0 0 x 0 x 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 1 0 0 x 0 0 1 0 0 0 0 0 1 0 0 0 1 0 0 1 0 x 0 0 0 1 0 0 1 0 0 1 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x 0 x x 0 0 0 0 x x x 0 x 0 x x x x x 0 0 0 0 1 0 0 0 0 0 0 0 x 0 0 1 0 0 x x 0 0 x x 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x x x x x 0 0 0 x x 0 x x x 0 0 0 x 0 0 x x x 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 x 0 0 0 0 0 x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 x 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x 0 0 x 0 0 x x x x 0 x x 0 x x 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 x x 0 x x x x x 0 0 0 x x x 0 x x x x 0 x x x x x x x x 0 x 0 x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 x x x 1 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x x x x x 0 0 0 0 x x 0 x 0 0 x x x x 0 x 0 x 0 0 0 x x x 0 0 0 0 x x 0 x 0 x 0 x x 0 x x x 0 0 0 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x x x x 0 0 0 x x x x x x 0 x x x x x x 0 x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 x 0 0 0 0 0 x 0 0 0 0 0 x x x x x x x x x x 0 x x x x x x x x 0 x x 0 x x 0 x 0 x x x x 0 x x 0 x x x x x x x x x 0 x x x 0 x 0 x x x x 0 x x x 0 x x x x x x x 0 x 0 x x x 0 x x x x x 0 x 0 0 0 0 0 x x 0 0 x x 0 x x x x x x x x x x x x x 0 0 0 0 x x x 0 0 0 0 x x 0 x x x 0 x x x 0 x x x x 0 x x x 0 x x x 0 x x x 0 x x x 0 x x x 0 x x x x 0 x x x 0 x x 0 x x x 0 x x x 0 x x 0 0 0 x x 0 x x x 0 x x x x x x x x x x x 0 x 0 x 0 x x x x x x x x x x x x x x x x 0 x 0 0 x x x x 0 0 x 0 x x 0 x x x x 0 0 0 x x x 0 x x x x x x x 0 0 x 0 x x x x x 0 x x x 0 x 0 0 x x 0 0 x x x 0 x x x 0 0 x x x x x x x 0 0 x x x x x x x x x x 0 x 0 x x x x x x x x x 0 0 x x x 0 x x x x x 0 0 x x x x x x x x x x 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x 0 x 0 x x 0 0 x x x 0 0 x x x x 0 0 x 0 0 x x x x x x x x 0 0 0 x x 0 x x 0 0 x x x 0 x 0 x x x 0 0 x x 0 x x x x x 0 x x x 0 x x x x x 0 x x x 0 x 0 0 x x x x x x 0 x x 0 x x x x x x 0 x x x 0 x x x x x x x 0 x x x x x 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x 0 0 0 0 1 x x 0 0 0 x x x 0 0 x x x x x x 0 0 x x x x x x x 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 1 0 0 1 0 x x x 0 x x x x x 0 0 x x 0 0 0 0 0 0 1 x x x x x x x x 0 0 0 0 0 0 x x 0 x 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 x x x x x x 0 0 0 x x x 0 x x 0 x x 0 0 0 0 0 0 x 0 x 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 x 0 x 0 x x x x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 1 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Gamehack.LOA

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN