Gridinsoft Logo

Forza-Mods-AIO.exe PUP GameHack Analysis

Technical Analysis

File Name Forza-Mods-AIO.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.217.174
Database Version 2025-06-05 04:00:44 UTC

PUP.Win64.GameHack.bot

Malware family: GameHack

GameHack refers to game modification tools that manipulate game mechanics to provide unfair advantages, violating game terms of service and fair play principles.
N/A
Detection Rate
9,659,763
File Size (bytes)
2025-06-05
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
195ff40538d94cb4b2fd07eac975af1e
SHA1
8fabef2156ac42d47bec2b45f5708d68bd1127d1
SHA256
16b34533718049f776521fd5eb9e1ac9269022df881182698d213a7b4fbf0d77
SHA512
2da1d8b62bf60c0f62c9947b02088a63153a35d8efa7f3de62059a18a114f8530efe7f6967c040891326595fd16aa3c11a074ae800dc2d8507c56004f3b68207
ImpHash
6a91eb82bfd19d2706c7d43c46f7064e

PE Analysis

Basic Information

Image Base 0x140000000
Entry Point 0x140011360
Compilation Time 2024-04-16 22:47:28
Checksum 0x00000000 (Actual: 0x0093c0bb)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
PDB Path D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb
Digital Signature No valid SignedData structure was found.
Imports 12 libraries
Exports 0 functions
Resources 2 Resources
Sections 7 Sections

Version Information

Translation 0x0000 0x04b0
CompanyName 34c36a19-d28f-44ca-9a82-bc271a143951
FileDescription 753e7101-1769-48e2-a59c-830aba8c8f84
FileVersion 2.4.0.1
InternalName 753e7101-1769-48e2-a59c-830aba8c8f84.dll
LegalCopyright
OriginalFilename 753e7101-1769-48e2-a59c-830aba8c8f84.dll
ProductName 50648d2e-f049-4250-bced-1c2a9b9f8c25
ProductVersion 1.0.0+c5a9ede5ef3a74e802e540a2daf0917d9124767d
Assembly Version 2.4.0.1

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 92,508 bytes 92,672 bytes 6.37 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 7FE5DF02C7C53B8E1AC373EEA024C1C9
.rdata 0x00018000 38,366 bytes 38,400 bytes 4.49 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 8EA3180A074B6EBA84C8A3A3F26C2312
.data 0x00022000 6,224 bytes 2,560 bytes 2.44 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 86D127F5C401B8EF29EEF72E1638CA95
.pdata 0x00024000 5,052 bytes 5,120 bytes 4.98 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 58B5C0BA22A038CA54D885829AB5F06D
_RDATA 0x00026000 500 bytes 512 bytes 4.21 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ F03E9BC08417A2C7013707183AF3D6F7
.reloc 0x00027000 792 bytes 1,024 bytes 4.70 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 8C0B631B1BF06E3A21B8F532673041EA
.rsrc 0x00028000 2,760 bytes 3,072 bytes 4.36 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 77A2E5D78F8350F74157F1AEB626ABD0

Resource Analysis

Total Resources: 2 (2,597 bytes)
Resource Type Count Total Size Percentage
RT_VERSION 1 1,068 bytes
41.1%
RT_MANIFEST 1 1,529 bytes
58.9%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

PUP.Win64.GameHack.bot Removal

Gridinsoft has the capability to identify and eliminate PUP.Win64.GameHack.bot without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware