PUP.MSIL.Gamehack.F

Analysis Report

General information

Family Name: PUP.MSIL.Gamehack.F
Signature status: No Signature

Known Samples

MD5: e9ba1d96877b242da75d7a3f37a50ef3
SHA1: 209fc79d82cdd5f4c058482297da7f07d5ec41ee
SHA256: BB4CAF1A1A9A2CACE222AD022973C9AB8C30CDE8238EEB4DBDF5BA0D7B0FFB12
File Size: 187.39 KB, 187392 bytes
MD5: 701dcbb1a69f438e4765a59b351ca1da
SHA1: edfc45f38487f66f3cf7dab85f2f5b767314e093
SHA256: 2620896CD3997FAA19D08463FA3C8787F5DD961EE97304A738FD7F1563E2C270
File Size: 275.97 KB, 275968 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Comments
  • Bot BC 155v3
  • KMX Bot BC Premium
Company Name
  • Bot BC 155v3
  • KMX Bot BC Premium
File Description
  • Bot BC 155v3
  • KMX Bot BC Premium
File Version 1.0.0.0
Internal Name
  • Bot BC 155v3.exe
  • KMX Bot BC Premium.exe
Legal Copyright
  • Copyright © 2023
  • Copyright © 2025
Legal Trademarks By:LUTOBI
Original Filename
  • Bot BC 155v3.exe
  • KMX Bot BC Premium.exe
Product Name
  • Bot BC 155v3
  • KMX Bot BC Premium
Product Version 1.0.0.0

File Traits

  • .NET
  • CreateThread
  • HighEntropy
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 265
Potentially Malicious Blocks: 171
Whitelisted Blocks: 76
Unknown Blocks: 18

Visual Map

x x 0 x 0 x x x x x x x x x x x x x 0 x x 0 0 0 x x x x x x x x x x x x x x 0 0 0 0 0 0 0 x x x x x x x x x x x x 0 0 0 0 0 ? x x 0 x x x x x x 0 ? ? ? ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? ? x 0 x x x x ? x x x x x ? ? x x x x x x x x 0 0 x x x x x x 0 x x x x 0 ? 0 x x x 0 x 0 x x x x x x ? x x x x 0 x x 0 0 0 0 x x x 0 0 0 0 0 0 x 0 0 0 x x 0 x 0 ? x x x x x ? x x x ? 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x x x x x ? x 0 ? 0 0 0 0 0 0 0 x 0 0 0 0 0 x x x x 0 0 0 0 ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.IRPlan.T

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider

Trending

Most Viewed

Loading...