PUP.MSIL.Gamehack.CJB

Analysis Report

General information

Family Name: PUP.MSIL.Gamehack.CJB
Signature status: No Signature

Known Samples

MD5: 5302430915263cbd6e68cc9c36f7ea6e
SHA1: 6b2314be4bbdf73af21a4f359d0083fe54765751
File Size: 32.77 KB, 32768 bytes
MD5: daa06e42988269b2fa88cdfd00168c41
SHA1: a976a4940fd9b23300ca416a78274dda042159dd
SHA256: A9D28AE929C2ACBC75A4A95CFFB54417F6920E2AD1F1FF40E18E66E6A3C547C4
File Size: 41.47 KB, 41472 bytes
MD5: c6a9996c613822d5dd3d8a3c69d82971
SHA1: ffc865199c445c257a27b43b058c155d59e41a66
SHA256: 3ED11B50AA548287BAD2DACCCCE3F71183968F90322044D06611B2DF767EB625
File Size: 67.58 KB, 67584 bytes
MD5: 842adc9b2083110c214b41873791191a
SHA1: 5e1da11d0d68af005b9fa32cc92fffc6a060b973
SHA256: 64C4C3D7CBC26F2FF5F8F2C7FD434207E770C5DBF04DA0D9B3DA640C6CAC5783
File Size: 47.10 KB, 47104 bytes
MD5: 687f7e95fd0136329c3406c45e6f07af
SHA1: a6fa7cb55294082ed86ab17a2d9ca9af7d6b9ec9
SHA256: 326D4DAB91C17F903010099B2CC1D87929D23DA032743475A36D914453DB2877
File Size: 65.02 KB, 65024 bytes
Show More
MD5: 46b508b32865780513c62d04cfa5ec02
SHA1: bd38b70fee72c748f624f1c80f32faf37a5eff89
SHA256: CE52E03C727799D59D2DA27695C47A1DC5402ED4094ED655805CB6424E1BD157
File Size: 31.23 KB, 31232 bytes
MD5: 5dd5b9cc823b3852d968dea52d2f703f
SHA1: 1f61af5065748bec314700a68d45223dd270f8af
SHA256: E40639310848B212864BB4201205EED98FFF4817717E9DD74C7AC4532295FC35
File Size: 40.45 KB, 40448 bytes
MD5: f179e660527b4388a078ca40a9682fc9
SHA1: aac36acd03392a16d1afcf3e1f81f33488429712
SHA256: AEAB4962AFECF5D1A3985D8A0BAA99D04BF46BA81C28AAEF9583B99CF24A853F
File Size: 72.70 KB, 72704 bytes
MD5: 91d44456ffc214d4aca3f17009897fe5
SHA1: f0d4eb95767cafd0edc96f4c1dcaf44ea6e12528
SHA256: C98858FC24F561668B51017B8A5B340D667DDE17DE17249182998F9D3C516E36
File Size: 688.13 KB, 688128 bytes
MD5: afda4f8f589b98fe84b130e5dd0d55e1
SHA1: 57f39f512f85357603a9b25d5aedeae010667e38
SHA256: BBCF1722E72F5C128BEE93523B2F215C21231CE03D952EA9DDDD8B2630B95B21
File Size: 66.56 KB, 66560 bytes
MD5: 86efb9af1e9e52380b372ccbb6d98be7
SHA1: c9bb3293e3aed9c65055ccc725dcf1d27bdffee8
SHA256: BBD9D80A8F05BA1F856BA7E0794C0D39E898D2603D6FA12482099E6BD8936B8A
File Size: 38.40 KB, 38400 bytes
MD5: b0feb1fb19421cd50a7f53f654add5f9
SHA1: 244d449085792cdd4dc7ca0212d27f4e4872a173
SHA256: 12A91AAFFAE30608F3DC03D94721F16F6AF314AC3A9B99E08FE4BF80C5E650E9
File Size: 955.39 KB, 955392 bytes
MD5: ff48e9dd3494261eb4879c121bbba73c
SHA1: d677293c149df65022eb42b8fb6243141753f62c
SHA256: 315BA653FD795900621F1CA6A8A37A01F722DBF37515DDF85DF9EE71C87F13C8
File Size: 54.78 KB, 54784 bytes
MD5: 0d123f024212b10011f26ee4b522768c
SHA1: 4ff7f4734afca7060b0e5d31833e234c589a93e0
SHA256: D935CBF37705EC260CD46AD14EB971F39C96C5D73328490518DAC4D0D31C4973
File Size: 420.86 KB, 420864 bytes
MD5: c592b5e63c26f130ce5372c267919e3a
SHA1: 7cd85d31bb3c5c5866bb24b77f87b024f1ba766f
SHA256: EB69C000DFB22DAE12B64D32AD6898A4000B8667624885CC950B7DFF7EEC765C
File Size: 103.94 KB, 103936 bytes
MD5: 505b061535034f1bab9a52beca679392
SHA1: fe2e16456e7c34f4bf6320a0305ec3d6649e42a6
SHA256: C09192FD868390087D0C845375AAB37797146765B3F529DBE7E6D0F2C1FE796C
File Size: 420.86 KB, 420864 bytes
MD5: c2ce5dd6035a87ca4d078fd0f250eb9c
SHA1: 99bf42b5b2a5d174ca757a76a032711e8e9a67e9
SHA256: AFA8E3F19FBEE72D574BF362F0DF467E15B3D3D7C785C1F05F776D45EB6562EF
File Size: 53.25 KB, 53248 bytes
MD5: 8204fc20925f45613c1c24536ed98e4a
SHA1: 87c5ae713a229f8d7ee13e7deef9af085acf20d8
SHA256: 27ECBAF591B9239EDFA231B3C94683973134106EB6C9AF04722A8E9E9FB2C1AE
File Size: 48.64 KB, 48640 bytes
MD5: a8dbef9cade230198f864024d7e1e3d0
SHA1: 0e570054086178ebe5130e3513ef5d40e956a501
SHA256: F417D2876CC34DD2EB5C929CBE7799C2C2197043A5037C24DCA0B33A8A0BE28D
File Size: 97.79 KB, 97792 bytes
MD5: 195b72e877bf2a31a8e251b52539947a
SHA1: 8f5d0c071b2b474fd018955a036816ec6cd93021
SHA256: D481B0289D926DAFEB4502C4D20377063EDCFFB639D7CAF061F6C60E73394EC9
File Size: 44.00 KB, 44004 bytes
MD5: 3f66e398c01a5aedf89e4178b968be04
SHA1: 069b2534d77916184f18478019f4121d6434f09c
SHA256: 802EF2A88E4E51BB15460D1E978E45F2151EC0130122FA4764A825B1409F1D26
File Size: 33.79 KB, 33792 bytes
MD5: 8d306efe4397858546531099e40de583
SHA1: 6ca230e3921d45ab221e9433ac18b240c423c143
SHA256: 79628F39E2B1F16C0116BC1EB82373F58399C07648D0BC36EB5B4747052E9E30
File Size: 32.26 KB, 32256 bytes
MD5: c8880431f50dfad38d17ad759731c12b
SHA1: 750e3ee05be99d1c025c8461550ecdc2d773d89d
SHA256: 51E1B7CC2F6C8110D6F35E204F8F876233D1DD3FD100B949A48E75F4AB11A958
File Size: 98.82 KB, 98816 bytes
MD5: 0ef3fdb062e05a3115da93d67613c273
SHA1: 8e27d3bedb0484ca4dac5f85cb7b3d5031f20dc0
SHA256: 7619C98DAE3562BED927E1D6034BFF75E916F48E50CA852FFACD7B27C1EB4E25
File Size: 986.69 KB, 986688 bytes
MD5: e06237bb7f2b50808bd0f9b3c3228a9c
SHA1: 90729519bb1fff45cfbc35eed3d6e68e2b3a9df7
SHA256: 58FFC3903CED3A10CD99450F1412DF57F3018C1DB33F4DF2A31B739ADF24A291
File Size: 368.64 KB, 368640 bytes
MD5: 75ac9cc52c1000d35e542b80fc48dc8a
SHA1: 3124a150fd23c4abf1bdbd60aa76a46aec45247a
SHA256: D987560801D4BD197EC17701882B9C32730C48728C7DEBE254094C9F316F2BAB
File Size: 67.07 KB, 67072 bytes
MD5: bf449f6848e612bc8f24c02dc9ecbbf7
SHA1: 0c4b27929c5096035b006f18c065d073f430fbe7
SHA256: 47251E31822CF7360375C19D165780F670A3E3634898E5146958105682217F78
File Size: 25.09 KB, 25088 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version
  • 5.7.0.0
  • 1.5.0.0
  • 1.0.0.0
Company Name
  • AetherTemp
  • Astro
  • CxH
  • DevCameraMod
  • eyerockreborn
  • goldentrophy
  • Gorilla Quests
  • GorillaSteps
  • iiCamMod
  • INFINITY
Show More
  • IRON
  • kfjsMenuTemp
  • KFM MENU
  • LS_MOD_Menu_V2.1
  • ModderX
  • sigmasMenu
  • StupidTemplate
  • SupermarketTogetherKacker
  • Utilla
  • WhoIsTalking
File Description
  • AetherTemp
  • Astro
  • CustomNotes
  • CxH
  • DevCameraMod
  • eyerockreborn
  • Gorilla Quests
  • GorillaSteps
  • ii's Stupid Menu
  • iiCamMod
Show More
  • INFINITY
  • IRON
  • kfjsMenuTemp
  • KFM MENU
  • LS_MOD_Menu_V2.1
  • ModderX
  • sigmasMenu
  • StupidTemplate
  • SupermarketTogetherKacker
  • Utilla
  • WhoIsTalking
File Version
  • 5.7.0.0
  • 1.5.0.0
  • 1.0.0.0
Internal Name
  • AetherTemp.dll
  • Astro.dll
  • CustomNotes.dll
  • CxH.dll
  • DevCameraMod.dll
  • eyerockreborn.dll
  • Gorilla Quests.dll
  • GorillaSteps.dll
  • ii's Stupid Menu.dll
  • iiCamMod.dll
Show More
  • INFINITY.dll
  • IRON.dll
  • KfjTemp.dll
  • KFM MENU.dll
  • LS_MOD_Menu_V2.1.dll
  • ModderX.dll
  • sigmasMenu.dll
  • StupidTemplate.dll
  • SupermarketTogetherKacker.dll
  • Utilla.dll
  • WhoIsTalking.dll
Legal Copyright Copyright © 2019
Original Filename
  • AetherTemp.dll
  • Astro.dll
  • CustomNotes.dll
  • CxH.dll
  • DevCameraMod.dll
  • eyerockreborn.dll
  • Gorilla Quests.dll
  • GorillaSteps.dll
  • ii's Stupid Menu.dll
  • iiCamMod.dll
Show More
  • INFINITY.dll
  • IRON.dll
  • KfjTemp.dll
  • KFM MENU.dll
  • LS_MOD_Menu_V2.1.dll
  • ModderX.dll
  • sigmasMenu.dll
  • StupidTemplate.dll
  • SupermarketTogetherKacker.dll
  • Utilla.dll
  • WhoIsTalking.dll
Product Name
  • AetherTemp
  • Astro
  • CustomNotes
  • CxH
  • DevCameraMod
  • eyerockreborn
  • Gorilla Quests
  • GorillaSteps
  • ii's Stupid Menu
  • iiCamMod
Show More
  • INFINITY
  • IRON
  • kfjsMenuTemp
  • KFM MENU
  • LS_MOD_Menu_V2.1
  • ModderX
  • sigmasMenu
  • StupidTemplate
  • SupermarketTogetherKacker
  • Utilla
  • WhoIsTalking
Product Version
  • 5.7.0
  • 1.5.0.0
  • 1.0.0+d6352385a261228a80c8eb401ef47e2997dcdbcc
  • 1.0.0+d283cd9446a1e6287abf0f4cabdf2ccb3371ace6
  • 1.0.0+a99cd38c32feef741fea35372ab9cda6f91e231d
  • 1.0.0+37697cf94cb2ec6c36642aac09efe1d3ad7a9809
  • 1.0.0+3844d2143af6f8722093d6e27a52a16e3592e77b
  • 1.0.0+530c3cebe66d2187291654a11b63c136560a0dc3
  • 1.0.0+365bf9e32ca4c85852c1e6376fb23f8d05a4be76
  • 1.0.0+17aa9743de8b9a4beff319e68c0ccfb0e61cf2c5
Show More
  • 1.0.0+14e15c464535d0889f232976054e810bca6fc218
  • 1.0.0+8ff7f968b2adad3ec6a53af34b8935eafc49802f
  • 1.0.0

File Traits

  • .NET
  • dll
  • HighEntropy
  • Pastebin
  • x86

Block Information

Total Blocks: 19
Potentially Malicious Blocks: 2
Whitelisted Blocks: 1
Unknown Blocks: 16

Visual Map

? 0 ? ? ? x x ? ? ? ? ? ? ? ? ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
Show More
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiRestoreDC
  • win32u.dll!NtGdiSaveDC
  • win32u.dll!NtGdiSelectBitmap
  • win32u.dll!NtGdiSetDIBitsToDeviceInternal
  • win32u.dll!NtUserBuildHwndList
  • win32u.dll!NtUserCallTwoParam
  • win32u.dll!NtUserCreateEmptyCursorObject
  • win32u.dll!NtUserCreateWindowEx
  • win32u.dll!NtUserDestroyWindow
  • win32u.dll!NtUserFindExistingCursorIcon
  • win32u.dll!NtUserGetAncestor
  • win32u.dll!NtUserGetClassInfoEx
  • win32u.dll!NtUserGetClassName
  • win32u.dll!NtUserGetDC
  • win32u.dll!NtUserGetGUIThreadInfo
  • win32u.dll!NtUserGetIconInfo
  • win32u.dll!NtUserGetIconSize
  • win32u.dll!NtUserGetImeInfoEx
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetObjectInformation
  • win32u.dll!NtUserGetProcessWindowStation
  • win32u.dll!NtUserGetProp
  • win32u.dll!NtUserGetThreadDesktop
  • win32u.dll!NtUserGetThreadState
  • win32u.dll!NtUserGetWindowCompositionAttribute
  • win32u.dll!NtUserIsNonClientDpiScalingEnabled
  • win32u.dll!NtUserIsTopLevelWindow
  • win32u.dll!NtUserMessageCall
  • win32u.dll!NtUserRegisterClassExWOW
  • win32u.dll!NtUserRegisterWindowMessage
  • win32u.dll!NtUserReleaseDC
  • win32u.dll!NtUserRemoveProp
  • win32u.dll!NtUserSelectPalette
  • win32u.dll!NtUserSetCursorIconData
  • win32u.dll!NtUserSetWindowFNID

3 additional items are not displayed above.

Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\8e27d3bedb0484ca4dac5f85cb7b3d5031f20dc0_0000986688.,LiQMAxHB

Trending

Most Viewed

Loading...