PUP.MSIL.Gamehack.AA

Analysis Report

General information

Family Name: PUP.MSIL.Gamehack.AA
Signature status: No Signature

Known Samples

MD5: c49043ad882865b85270f12f4e9ed700
SHA1: 008e734aaa3ca307f8a1b1aa6f9a22e22cfb6479
SHA256: 3DD3D3D593C1F8C0C480E0E87BB153875278947724B2E4F52DD970A3F8F5DF13
File Size: 290.30 KB, 290304 bytes
MD5: 206db647a8db45f0a9a93eb389a2f4db
SHA1: 9fa5d8ca0a24a34e612e900255572dcaa4c899ab
SHA256: FA463DF3D4DC7307035A222347BE7327987AF95285C7B31714E467EBAEEFD97E
File Size: 290.30 KB, 290304 bytes
MD5: 28802e1fdd9e80599cb8c29eb6dce564
SHA1: 8f87477cebda6b20341cac719526cca2d0d5c630
SHA256: B887DA3ABC609CBDF35CA54F4411DB68F6914E126D76D6CC9180AB13ADDABEF6
File Size: 225.79 KB, 225792 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Comments Calculator by Ruben Roy
Company Name RubiconT
File Description
  • Calculator
  • combo convertor
File Version 1.0.0.0
Internal Name
  • Calculator.exe
  • combo convertor.exe
Legal Copyright
  • Copyright © 2023
  • Rubicon Copyright © 2016
Original Filename
  • Calculator.exe
  • combo convertor.exe
Product Name
  • Calculator
  • combo convertor
Product Version 1.0.0.0

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 12
Potentially Malicious Blocks: 1
Whitelisted Blocks: 8
Unknown Blocks: 3

Visual Map

0 ? x ? 0 0 ? 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider

Trending

Most Viewed

Loading...