PUP.MSIL.Gamehack.GDI

Analysis Report

General information

Family Name: PUP.MSIL.Gamehack.GDI
Signature status: No Signature

Known Samples

MD5: 466d5e30b5c78e71ccc7d4ad702308ba
SHA1: 31bd71c696247bcedb038fe2b758d528b39fd585
SHA256: 60B2E151179DCE2C148CFBB84CF3BD33512554CDD2E1C3FE69E6F0F929B993AD
File Size: 2.36 MB, 2355200 bytes
MD5: e3716aceafa6ff2589801bd51e6452a9
SHA1: 5980e5f51d8938a34e9a4466724f62def065b0fa
SHA256: 0A07CB5C2510684BBC76C6B77C9DDB457175BCD1F63403E3E13CD67B20D7090E
File Size: 1.98 MB, 1977856 bytes
MD5: 784f79b56cf1d42b298ad129c608cc37
SHA1: 99bd4a6ad7c2d94ebf07804c4e7a1dbe16a82b86
SHA256: DAA5EA9889B4F2A33D3D989C702A587F96AC0E206BB0C4B4B008590835DBC070
File Size: 1.96 MB, 1961472 bytes
MD5: c7214e7d99bd93b3283a0dda4141dd65
SHA1: 5622d7c8708da8fcd33313f26da1436f27037bd1
SHA256: F5F359611E86C4EBECDF1FD1D1458428C633699A9BB9F50F49ECBD945C14E507
File Size: 1.81 MB, 1808384 bytes
MD5: e48825d391fdaa842426f049fd96c31a
SHA1: 47ec820521a1ca65b41fc105e625f7bbdd173c2d
SHA256: 0A3E883CF30453C855C6B2DB1D8C1DB9938502EE99CA46A9E88DB0AAB8A08718
File Size: 3.60 MB, 3603968 bytes
Show More
MD5: 8270b2675343857988c6e7287ca917cb
SHA1: 417c613b1020a304b336280debe325c535e997f4
SHA256: E3DECE9152687B816AF400E8F32220F9F443D5451D1A34D061BD2E7FC8CF171F
File Size: 2.11 MB, 2113024 bytes
MD5: 8485dbbc52f24ee17b3fe6f1eb52897e
SHA1: d507d2bbaf8ca555a3273a1a919aecbc24a44067
SHA256: CDB9810D6218383B224CB852E6F34399B6B5754158820412546AA8BE18FAD531
File Size: 4.43 MB, 4428800 bytes
MD5: 183296b3de578c13105faeed3cd462b8
SHA1: 06140e6b4272c557d089442caab20fc16831b29c
SHA256: AED604D30BAA8E05BC19AD4A9195504801DBF6A14742364F0D459C4AE4CBD53D
File Size: 7.41 MB, 7407104 bytes
MD5: fb2e93af000198b27ebe6801b1e5b733
SHA1: 0a9f2260b7e2f2499f03db59176847efd1fd59eb
SHA256: 76C706031A569274A2E8B0F54DD4DB783E023E73C5CFABCF1846C1A2A79428DA
File Size: 7.70 MB, 7696384 bytes
MD5: f3c26891286d3cdfe42e94a57e061014
SHA1: 3585764227aaa80738b5ce02545a68575e4cddfb
SHA256: 82C54600048C51635AF93CD1E23A2E4227FE424DCB76F9967C9FEEFAFFA92197
File Size: 1.94 MB, 1935872 bytes
MD5: 368c1da86b2763c01016b3b59dbfae11
SHA1: d1a959c5d0ae96b0060f9f6aa470412b251d8daf
SHA256: F9C0D3C8FDE7F944FB82D098BF2A18EE127A66A5498A1BA2DF4020B92000E6CA
File Size: 8.73 MB, 8728576 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Company Name
  • Elysor
  • Illusion
  • KXR
  • silliness
  • Spectral Menu
  • TGSGhostts Temp
File Description
  • Arctic Template
  • Elysor
  • Illusion
  • Interstellar
  • KXR
  • silliness
  • Spectral Menu
  • TGSGhostts Temp
File Version 1.0.0.0
Internal Name
  • Arctic Template.dll
  • Elysor.dll
  • Illusion.dll
  • Interstellar.dll
  • KXR.dll
  • silliness.dll
  • Spectral Menu.dll
  • TGSGhostts Temp.dll
Legal Copyright
  • Copyright © 2023
  • Copyright © 2024
Original Filename
  • Arctic Template.dll
  • Elysor.dll
  • Illusion.dll
  • Interstellar.dll
  • KXR.dll
  • silliness.dll
  • Spectral Menu.dll
  • TGSGhostts Temp.dll
Product Name
  • Arctic Template
  • Elysor
  • Illusion
  • Interstellar
  • KXR
  • silliness
  • Spectral Menu
  • TGSGhostts Temp
Product Version
  • 1.0.0.0
  • 1.0.0+66d942d890e26c3e874ae2e529c2d7fa6fccfe40
  • 1.0.0+3d6bab7429b8fd5e02d395eac12d173002cdaeee
  • 1.0.0+3cb94ff03adcd6e4301f0a7d3b833d55d9241b78
  • 1.0.0

File Traits

  • .NET
  • dll
  • Pastebin
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 16,286
Potentially Malicious Blocks: 2,655
Whitelisted Blocks: 8,177
Unknown Blocks: 5,454

Visual Map

x 0 0 0 0 ? ? ? 0 ? 0 0 0 ? x 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 x 0 0 0 ? 0 ? 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 x 0 ? ? ? ? 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? ? ? ? 0 ? ? ? 0 ? 0 0 0 x 0 ? ? 0 ? 0 x ? 0 ? ? ? x ? ? 0 0 x 0 ? 0 ? x ? ? ? x ? 0 ? 0 ? 0 0 0 ? ? ? ? 0 ? x 0 ? 0 0 ? x 0 ? x ? x ? 0 0 ? x x ? ? x x 0 x 0 0 0 ? 0 0 0 ? 0 x ? 0 ? ? x ? 0 0 ? x ? x 0 ? ? ? ? x ? x ? x ? 0 0 ? ? 0 ? ? ? 0 0 x ? ? x ? ? ? 0 ? 0 0 ? ? ? 0 0 0 x x ? ? ? 0 x 0 ? ? ? ? ? 0 ? x 0 0 x x ? 0 ? ? x ? x 0 ? 0 0 ? ? ? 0 x ? 0 0 ? ? x 0 ? ? ? 0 ? ? x x ? ? ? x ? x 0 0 ? x x 0 x 0 x 0 0 x 0 x x ? ? ? ? ? 0 0 ? 0 0 ? 0 x ? 0 x 0 0 0 ? 0 0 x x ? 0 ? x ? ? ? ? 0 ? ? 0 ? ? 0 x ? 0 ? 0 0 x x x 0 ? ? ? 0 x 0 ? 0 x ? 0 ? ? ? ? 0 0 0 0 ? ? ? ? 0 ? ? 0 ? 0 ? ? x ? ? x 0 0 ? 0 x ? 0 x x x 0 x 0 x ? 0 x x 0 0 0 0 x x 0 x ? ? x ? ? 0 ? x x x ? ? ? ? 0 0 ? ? 0 ? ? ? ? 0 0 x 0 0 ? ? x x 0 0 ? x ? ? ? 0 ? x 0 0 0 0 ? ? ? x 0 x 0 ? ? x ? x 0 x x ? ? ? 0 x x x ? 0 x ? ? ? x 0 0 ? x 0 ? ? ? x 0 ? ? 0 0 ? ? ? x x ? 0 0 0 0 ? 0 0 0 x x x ? x 0 0 0 x 0 ? ? x x ? x x x 0 ? 0 x ? x x 0 x ? 0 x 0 0 0 x ? 0 0 0 ? x ? ? 0 x ? 0 ? ? 0 ? ? ? ? ? x 0 ? x 0 0 ? ? 0 ? 0 0 x ? ? 0 ? 0 x x ? 0 ? 0 0 0 ? x x ? 0 ? ? x ? x 0 x 0 0 ? ? x x 0 ? x ? ? 0 ? ? ? 0 0 ? ? 0 ? x x x 0 0 0 0 x 0 ? x 0 ? ? 0 ? 0 ? ? x ? 0 ? 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 x x ? ? x x x x ? ? ? ? ? ? x x 0 0 x 0 0 0 ? ? 0 x 0 ? ? x ? ? ? ? ? ? 0 ? x x ? ? x ? 0 ? 0 ? ? ? x ? 0 ? 0 x 0 ? 0 ? ? 0 ? x 0 x ? x x ? 0 ? ? x x 0 ? 0 0 ? x 0 x 0 ? x ? ? 0 ? x x ? x 0 0 ? x x x x ? 0 0 x 0 x x ? x 0 x 0 0 x ? ? ? ? ? ? 0 x ? x ? x 0 ? ? ? ? 0 x x ? x ? 0 x ? x ? ? 0 x ? 0 x ? 0 ? 0 ? 0 ? 0 x ? 0 ? x ? ? ? ? x 0 ? ? ? ? x x x ? 0 0 ? x ? x ? ? ? ? x 0 x 0 x ? ? ? 0 ? ? ? 0 ? 0 ? 0 x ? 0 ? ? ? ? ? ? x 0 0 x ? 0 ? x x 0 x 0 ? ? ? ? ? ? ? ? ? x 0 ? ? 0 ? 0 ? ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 ? ? 0 x x ? x x 0 ? ? ? 0 ? ? 0 ? ? 0 ? 0 0 0 0 ? ? ? ? x x 0 0 0 0 ? ? 0 x x 0 x x x 0 ? x 0 0 ? 0 0 0 ? 0 ? x x ? ? 0 x ? x 0 x x x 0 ? 0 0 0 ? ? ? ? ? ? ? ? 0 ? ? 0 x ? ? 0 ? 0 ? x x ? ? 0 ? 0 0 x 0 x x ? ? 0 x ? ? ? ? 0 x 0 ? x 0 ? x ? 0 ? 0 ? ? ? x ? 0 ? ? x ? x 0 ? ? ? ? ? x ? 0 ? ? x ? ? 0 ? x 0 ? x ? 0 ? ? ? x x ? ? ? 0 0 ? x ? ? 0 x 0 0 0 ? ? 0 ? ? ? ? 0 0 x ? x ? x ? 0 ? 0 x 0 0 0 0 ? ? ? ? 0 ? 0 0 x ? ? x ? x x ? ? x 0 ? x 0 0 ? 0 0 x 0 ? ? x x ? x x x ? 0 0 ? 0 0 0 0 ? ? x x 0 ? 0 0 ? ? 0 ? ? x ? ? 0 ? ? ? 0 ? 0 0 ? ? ? ? ? ? 0 0 0 ? ? x ? x ? 0 ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? x x ? 0 ? ? 0 0 ? ? 0 ? ? ? ? ? ? ? 0 x x ? x x ? 0 0 x 0 ? ? 0 ? ? ? ? ? ? x x x ? 0 0 x x ? ? ? 0 ? ? ? ? ? 0 0 0 ? x ? ? ? 0 ? 0 x ? x 0 0 ? ? 0 ? ? 0 0 x ? 0 0 ? x 0 0 0 ? ? x 0 ? x ? ? ? x ? x ? x x 0 ? ? 0 0 0 ? 0 ? x ? x ? ? 0 x ? ? ? ? ? ? 0 0 x 0 x ? ? 0 0 0 x ? 0 0 x ? ? ? x 0 0 ? 0 ? ? ? x x 0 ? ? 0 ? 0 ? ? ? 0 ? x ? 0 0 ? ? ? ? x ? ? ? x 0 ? ? ? x ? x x 0 ? ? 0 0 0 ? ? ? ? 0 x 0 ? ? 0 ? ? 0 0 0 ? ? ? 0 ? ? ? ? 0 ? x ? 0 0 0 ? ? ? ? x 0 ? ? ? ? x 0 x x ? x ? 0 ? 0 0 x 0 x ? x ? ? ? 0 0 0 ? ? x ? 0 0 0 ? ? ? ? ? ? ? 0 x ? 0 ? x ? x 0 0 ? x 0 ? 0 ? 0 ? ? 0 ? ? x 0 0 ? ? 0 ? x ? 0 x ? 0 x x ? 0 ? x ? 0 0 ? 0 0 0 x 0 ? ? 0 x ? ? x x ? ? ? ? 0 0 0 x ? ? 0 0 ? x ? 0 x ? ? x ? ? ? ? 0 0 x ? 0 0 ? x x 0 0 ? ? ? 0 ? x ? ? 0 ? 0 x ? 0 0 ? 0 ? 0 0 ? ? ? ? ? x ? ? ? ? 0 ? x ? 0 ? ? ? 0 x ? 0 0 ? ? 0 0 ? x ? ? x ? ? x 0 0 ? x 0 ? ? x 0 x ? ? ? 0 ? x 0 ? ? ? x x ? 0 ? ? ? 0 ? x 0 ? ? x ? x ? 0 ? x ? x ? ? ? x x ? x x x ? ? x ? 0 0 ? 0 ? ? x x ? x ? 0 ? ? x ? x x x x 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 ? 0 0 x 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 ? 0 0 x 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 x 0 0 ? ? 0 x 0 0 0 0 0 ? ? 0 0 x 0 0 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 x 0 0 ? x 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 x 0 0 0 0 0 ? 0 0 0 0 0 0 x 0 0 0 ? 0 ? 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 0 0 0 0 x ? 0 0 ? 0 ? 0 ? ? ? 0 ? 0 ? x 0 ? 0 0 0 0 0 0 0 0 x ? ? 0 0 ? 0 0 0 ? ? 0 x ? ? 0 ? 0 0 ? ? 0 x ? 0 ? ? 0 ? 0 0 0 x ? 0 ? 0 0 ? 0 x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Gamehack.CJN
  • MSIL.Gamehack.GDI

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiRestoreDC
  • win32u.dll!NtGdiSaveDC
  • win32u.dll!NtGdiSelectBitmap
  • win32u.dll!NtGdiSetDIBitsToDeviceInternal
  • win32u.dll!NtUserBuildHwndList
  • win32u.dll!NtUserCallTwoParam
  • win32u.dll!NtUserCreateEmptyCursorObject
  • win32u.dll!NtUserCreateWindowEx
  • win32u.dll!NtUserDestroyWindow
  • win32u.dll!NtUserFindExistingCursorIcon
  • win32u.dll!NtUserGetAncestor
  • win32u.dll!NtUserGetClassInfoEx
  • win32u.dll!NtUserGetClassName
  • win32u.dll!NtUserGetDC
  • win32u.dll!NtUserGetGUIThreadInfo
  • win32u.dll!NtUserGetIconInfo
  • win32u.dll!NtUserGetIconSize
  • win32u.dll!NtUserGetImeInfoEx
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetObjectInformation
  • win32u.dll!NtUserGetProcessWindowStation
  • win32u.dll!NtUserGetProp
  • win32u.dll!NtUserGetThreadDesktop
  • win32u.dll!NtUserGetThreadState
  • win32u.dll!NtUserGetWindowCompositionAttribute
  • win32u.dll!NtUserIsNonClientDpiScalingEnabled
  • win32u.dll!NtUserIsTopLevelWindow
  • win32u.dll!NtUserMessageCall
  • win32u.dll!NtUserRegisterClassExWOW
  • win32u.dll!NtUserRegisterWindowMessage
  • win32u.dll!NtUserReleaseDC
  • win32u.dll!NtUserRemoveProp
  • win32u.dll!NtUserSelectPalette
  • win32u.dll!NtUserSetCursorIconData
  • win32u.dll!NtUserSetWindowFNID
  • win32u.dll!NtUserSetWindowLongPtr
  • win32u.dll!NtUserSetWindowPos
  • win32u.dll!NtUserUpdateInputContext

Trending

Most Viewed

Loading...