Gridinsoft Logo

EMP.dll Hack GameHack Analysis

Technical Analysis

File Name EMP.dll
File Type
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Scanner Version 1.0.190.174
Database Version 2024-09-22 14:00:25 UTC

Hack.Win64.GameHack.ns

Malware family: GameHack

GameHack refers to game modification tools that manipulate game mechanics to provide unfair advantages, violating game terms of service and fair play principles.
N/A
Detection Rate
5,173,760
File Size (bytes)
2024-09-22
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
d90b6219918c6142174fbac8ffbccaeb
SHA1
ea5fe96f0dcbb08f1ea8bf14aa1158a8535efe86
SHA256
0aaa04c369f8377430ca14b24ab196da9fb0b012f71c22e2d1e62a928a7d2176
SHA512
e30a9bcbf41a32297f6bb6c361bf21c611d684af2bec93ceabf170dbcfc2cb3993b14c2d2017cbc448c73fd3a08759171ab130f1b20fa011a9b28b6f021e0cef
ImpHash
fc7124d57387852c0a6a634e9130bf57

PE Analysis

Basic Information

Image Base 0x13000000
Entry Point 0x13001334
Compilation Time 2022-02-17 20:24:51
Checksum 0x00000000 (Actual: 0x004f617b)
OS Version 6.0
PEiD Signatures PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Digital Signature The PE file does not contain a certificate table.
Imports 1 libraries
KERNEL32
Exports 1 functions
Resources 1 Resources
Sections 14 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 4,096 bytes 3,584 bytes 5.35 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 45C249E975C191DE18C9A3D7B61B0E58
.rdata 0x00002000 4,096 bytes 3,072 bytes 4.66 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ E29547AEDE5ECA82B4843C8900DEB575
.data 0x00003000 4,096 bytes 512 bytes 0.45 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 3E54B380C18E9FB1C3756C3724029E08
.pdata 0x00004000 4,096 bytes 512 bytes 5.90 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ FA2936DE519C38AAEA42F6EED022F577
.emp0 0x00005000 4,096 bytes 512 bytes 7.36 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 7348E1C79B7F00317D97D6BF9EA70699
.data2 0x00006000 94,208 bytes 94,208 bytes 0.28 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 8BDF4E4AA974B2D868EB2F47788FD2FA
.EMP 0x0001d000 208,896 bytes 208,896 bytes 0.52 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 101778FAED4C6EEA54A1BCAB5B087ABA
.data3 0x00050000 626,688 bytes 626,688 bytes 0.57 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 69897897448CC745CD4E5EDE01C9AEEA
.emp1 0x000e9000 1,115,444 bytes 1,115,648 bytes 6.95 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 2245A2D6618FFD2612FD2333DAF73D93
.emp0 0x001fa000 1,036,516 bytes 1,036,800 bytes 6.84 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ FA2317DEB8FBC85F5EB8D6BE2DBCF6C3
.emp0 0x002f8000 1,039,668 bytes 1,039,872 bytes 6.83 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 042DE33470ADC1FD097265C03B5A1BD6
.emp0 0x003f6000 1,040,468 bytes 1,040,896 bytes 6.84 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ BE52C96BC5DF482148375A1BBD707D9A
.reloc 0x004f5000 648 bytes 1,024 bytes 2.93 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 794446769326E8203720F166D85D2437
.rsrc 0x004f6000 233 bytes 512 bytes 2.53 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ C48F01D70944F8BC1259288C9E5FA8B4
Entropy Analysis Alert

5 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 1 (145 bytes)
Resource Type Count Total Size Percentage
RT_MANIFEST 1 145 bytes
100%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Hack.Win64.GameHack.ns Removal

Gridinsoft has the capability to identify and eliminate Hack.Win64.GameHack.ns without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware