PUP.MSIL.Gamehack.JPA

Analysis Report

General information

Family Name: PUP.MSIL.Gamehack.JPA
Signature status: No Signature

Known Samples

MD5: 62dba0927f96b98db243903d89a09be6
SHA1: 9b70cde9c9f157ccd6ac30500d83815510ca7cda
SHA256: 15FEC445740EB7C15A2656B51D02E6C2D74193BCA62F8D1C77993FF7130E308E
File Size: 2.16 MB, 2160640 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Company Name LethalMenu
File Description LethalMenu
File Version 1.0.0.0
Internal Name LethalMenu.dll
Original Filename LethalMenu.dll
Product Name LethalMenu
Product Version 1.0.0+91740069fbf5212d71c8989ac0bbef156f4caa23

File Traits

  • .NET
  • dll
  • x86

Block Information

Total Blocks: 1,134
Potentially Malicious Blocks: 846
Whitelisted Blocks: 288
Unknown Blocks: 0

Visual Map

0 0 0 x x x x x 0 0 0 x 0 0 x 0 x 0 0 0 0 0 x x x x x x x x x x 0 0 0 x x x x 0 0 0 x x x x x x x 0 x 0 x x x x x x x x x x 0 x 0 x x x x x x x x x x x 0 x x x x x x x x x x x x x x 0 x 0 x x x x x x x x 0 x x x x x x x x 0 x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x 0 x x x 0 x x 0 x x 0 x 0 x 0 0 x 0 x x x x x x x x 0 x x 0 0 x 0 x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x 0 x x x x x x x x x x x x x x x x x x x x 0 0 x x x x 0 0 x x 0 x x x x x x x x 0 0 x 0 x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x 0 x 0 x x x x x 0 x 0 0 0 x x 0 x x x 0 0 x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x 0 x 0 x x x 0 x 0 x x x x x x x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x 0 0 x x x x x x 0 0 x x x x x x x x x x x x x 0 x x x x x x x x x x 0 x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 x x x x x x x x x x x x x 0 x x x x x x x x x 0 0 x 0 0 0 x x x x x x x 0 0 x 0 x 0 x x x x x x x x x x 0 x x 0 x x x x x x x x x x x x x x x 0 0 x x x x x x x x x x x x 0 x x x x x x x 0 x x x x x x x x x x x x x x x x x x x 0 0 0 x x 0 x 0 0 0 0 0 0 x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x 0 x x 0 0 x x x x 0 x x x 0 x x 0 x 0 x x x x x x 0 x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x 0 x 0 x 0 x 0 x x 0 0 x x x x x x 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 x x x 0 x x x x 0 x x x x x x x 0 0 0 x 0 0 0 x 0 0 0 0 0 x x x x x x x 0 x x x x x x x x x x 0 x x 0 x x x x 0 x x x 0 x x x x x x x 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 x x x 0 x x x x 0 0 x x x x x x 0 x x x x x x x x 0 x x 0 x 0 x 0 0 x 0 x x x x x x x x 0 0 0 x 0 0 x x x x x 0 x x 0 x x 0 0 x 0 x x x x x 0 0 x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x 0 x 0 x x 0 x x x x x 0 x x x x 0 0 0 0 0 x 0 x 0 x x x x 0 x x x x x 0 x x x x x x x x x x x 0 0 0 x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Gamehack.JPA

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...