PUP.MSIL.Gamehack.YC
Table of Contents
Analysis Report
General information
| Family Name: | PUP.MSIL.Gamehack.YC |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
82f239a33af9a606a45bcb1e35d6dc8d
SHA1:
10a9c4dc124b5c5905543ea237c84711f4a936d0
SHA256:
DA62DDDEAA65CB1E29E8D502FBBD1F1F6BE7D5A68374CE489D9B0F671BBBD942
File Size:
4.18 MB, 4176384 bytes
|
|
MD5:
e38ebbc3b27e0e01b3f904b5ac832fd5
SHA1:
1087e1f3533ff743cfca7dff570daffcef12665d
SHA256:
966D0FBF53DF863D118440F3B6148EC290B2FD5D4A28FFF5D74E8F83DF343202
File Size:
6.06 MB, 6056960 bytes
|
|
MD5:
7e83e72548a900c242765bd494410aeb
SHA1:
fdf2e4e499d451166581c731956824f9fc25ce45
SHA256:
D4EAB0F6FA163AB1EA245EF8CBE2AF8C0F5360779CBCADE03E31AEC68A12A356
File Size:
5.62 MB, 5618688 bytes
|
|
MD5:
bdcaf06b8c7b2a785aec8ae90db08ecd
SHA1:
9a3079b2473b99bd0169fdf5bb96c0cd63804670
SHA256:
75678616E7744E37951AFFC3DF7C503E2AD5439AB8DB7D473106D147F722B2D0
File Size:
4.11 MB, 4106240 bytes
|
|
MD5:
3e4c28e5936170b9acf6d09a096d6915
SHA1:
d1d0bb8a4fefc912d9200cd6b9fbe9b72e484857
SHA256:
C6A7DBB5C8D6A17A8FF5017A2B14A00063FC3EDA8E12156AE0D52F83D75888BB
File Size:
5.28 MB, 5282304 bytes
|
Show More
|
MD5:
da4870bf25b24cc4655ae6dfd7c6febd
SHA1:
479fc5e04d499741e55dca3eb3554fc76a607523
SHA256:
69B4E39C84566FEA85E3C53A73DA1F338305358D339DD9D21471818D9D27431A
File Size:
6.06 MB, 6056960 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have security information
- File is .NET application
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Assembly Version |
|
| Comments |
|
| Company Name |
|
| File Description |
|
| File Version |
|
| Internal Name | Launcher.exe |
| Legal Copyright |
|
| Original Filename | Launcher.exe |
| Product Name |
|
| Product Version |
|
File Traits
- .NET
- HighEntropy
- RijndaelManaged
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 302 |
|---|---|
| Potentially Malicious Blocks: | 100 |
| Whitelisted Blocks: | 187 |
| Unknown Blocks: | 15 |
Visual Map
x
0
x
0
x
0
x
0
0
0
x
0
x
0
x
0
0
0
x
0
0
0
0
0
x
0
0
0
x
0
0
0
0
?
0
0
0
0
0
0
0
0
0
0
0
x
0
x
0
x
x
x
0
0
0
0
x
x
0
0
?
x
x
x
x
x
x
x
x
x
x
x
0
0
x
0
x
0
x
0
0
0
x
x
0
x
0
0
0
0
x
0
0
0
0
0
x
0
0
x
x
x
0
x
x
x
x
x
0
0
0
0
x
0
0
0
x
0
x
0
0
x
0
0
0
0
0
0
x
0
0
0
x
x
x
0
0
x
x
0
0
0
0
x
x
0
0
x
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
x
x
0
0
0
0
0
0
0
?
?
x
x
0
0
0
0
0
0
0
0
0
?
?
x
?
x
x
x
0
x
x
x
0
x
0
0
0
0
0
0
0
0
0
0
0
x
?
0
0
0
0
0
0
?
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
x
x
?
x
x
x
x
x
x
x
x
?
x
?
x
x
x
x
x
x
x
?
?
?
x
0
0
0
0
0
x
0
x
x
0
x
x
x
0
0
0
x
0
0
0
x
0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block
? - Unknown Block
x - Potentially Malicious Block
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\namedpipe\gmdasllogger | Generic Write,Read Attributes |
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\windows\appcompat\programs\amcache.hve | Read Data,Read Control,Write Data |
| c:\windows\appcompat\programs\amcache.hve | Write Attributes |
| c:\windows\appcompat\programs\amcache.hve.log1 | Read Data,Write Data |
| c:\windows\appcompat\programs\amcache.hve.log2 | Read Data,Write Data |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\system\software\microsoft\tip\aggregateresults::data | 馐ʊ耀Ś T 隞̃耀꧌ є 2 | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\system\software\microsoft\tip\aggregateresults::data | 鐄ȴ 鲱 綗 픋˹耀뫹躧 隞̃ﴁ耀꧌ Ѭ ĥ | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| User Data Access |
|
| Anti Debug |
|
| Process Shell Execute |
|
| Encryption Used |
|
| Process Manipulation Evasion |
|
| Syscall Use |
Show More
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 884
|
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 692
|
C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 876
|
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 840
|