The Scropts QOL v2 3 1 [unknowncheats me] dll File Malware Analysis
Gridinsoft Logo

The Scropts QOL v2.3.1_[unknowncheats.me]_.dll File Analysis

Technical Analysis

File Name Scropts QOL v2.3.1_[unknowncheats.me]_.dll
File Type
Win32 DLL
Magic Bytes PE32+ executable (DLL) (console) x86-64, for MS Windows
SSDEEP Hash
24576:ycmy0/ECpYgDghIMWqI30nXRtnqrX4SnFof:ycmhHYSH0fnO6
Scanner Version 1.0.225.174
Database Version 2025-09-23 10:00:24 UTC

Suspicious File Detected

Detected by 29 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.

GameHack refers to game modification tools that manipulate game mechanics to provide unfair advantages, violating game terms of service and fair play principles.
40%
Detection Rate
1,222,144
File Size (bytes)
29/72
Engines Detected
2025-09-23
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
b0b65c75d0f0b571fd5270c6b0479077
SHA1
e3efdc891f3fc13f23fa15f6303c97cecbca949e
SHA256
5998d5a09a0b334767623a369fb3839cb150326d83156eec6daf95c0d9c0e2f7
SHA512
7a9cb7a1b3f4756dade3df79f9e8a04c3ee23b8270cfd356f55d6ced3a1fe1f5cd21613abc743380958bea531cfbeba7c309279252d3e49cbd33c73052f83140
ImpHash
f2882cafb1f296e19c4550d18381fdb8

Security Engines with Detections (29 of 72)

Bkav
W64.AIDetectMalware Malicious
Lionic
Adware.Win32.GameHack.2!c Malicious
MicroWorld-eScan
Adware.GenericKD.61084192 Malicious
CAT-QuickHeal
Trojan.Ghanarava.1758319014479077 Malicious
Skyhigh
BehavesLike.Win64.Generic.th Malicious
ALYac
Adware.GenericKD.61084192 Malicious
Sangfor
Riskware.Win32.Gamehack.V75i Malicious
CrowdStrike
win/malicious_confidence_60% (D) Malicious
Symantec
PUA.Gen.2 Malicious
ESET-NOD32
a variant of Win64/Riskware.GameHack_AGen.S Malicious
TrendMicro-HouseCall
TROJ_GEN.R002H01I825 Malicious
Paloalto
generic.ml Malicious
BitDefender
Adware.GenericKD.61084192 Malicious
Rising
Hacktool.GameHack!8.59E (CLOUD) Malicious
Emsisoft
Adware.GenericKD.61084192 (B) Malicious
Google
Detected Malicious
VIPRE
Adware.GenericKD.61084192 Malicious
McAfeeD
ti!5998D5A09A0B Malicious
CTX
dll.hacktool.agen Malicious
Sophos
Generic Reputation PUA (PUA) Malicious
GData
Adware.GenericKD.61084192 Malicious
Varist
W64/ABTrojan.NIPJ-4743 Malicious
Arcabit
Adware.Generic.D3A41220 Malicious
Microsoft
Trojan:Win32/Kepavll!rfn Malicious
Cynet
Malicious (score: 100) Malicious
TrellixENS
Artemis!B0B65C75D0F0 Malicious
MaxSecure
Trojan.Malware.345033516.susgen Malicious
Fortinet
Riskware/GameHack_AGen Malicious
DeepInstinct
MALICIOUS Malicious
43 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Image Base 0x180000000
Entry Point 0x1800770dc
Compilation Time 2025-08-26 11:00:39
Checksum 0x00000000 (Actual: 0x0012e4cf)
OS Version 6.0
PEiD Signatures PE32+ executable (DLL) (console) x86-64, for MS Windows
PDB Path C:\Users\Scropts\Desktop\New folder\Scropts-QOL-main\x64\Release\Scropts QOL.pdb
Digital Signature No valid SignedData structure was found.
Imports 16 libraries
Exports 0 functions
Resources 1 Resources
Sections 8 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 497,667 bytes 498,176 bytes 6.45 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ C89BA2D7FD799682FC2EC5163BB6091E
.rdata 0x0007b000 347,912 bytes 348,160 bytes 6.30 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ EE5628FD5B70B940832E577743E516B0
.data 0x000d0000 344,152 bytes 340,992 bytes 5.51 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 0DF27BAB04B051514601AA436CEB3F76
.pdata 0x00125000 20,796 bytes 20,992 bytes 5.86 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 00F5A9BB04DE8A624EE9E9CEDAB81C94
.detourc 0x0012b000 8,720 bytes 9,216 bytes 2.89 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D80D749CC8FCB84B4151BA19437A6F1E
.detourd 0x0012e000 24 bytes 512 bytes 0.12 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE EDDA25907019E5CC74C177F6952E5E4B
.rsrc 0x0012f000 480 bytes 512 bytes 4.72 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ FE043BA89DA8C5FBF4AD81C451846D05
.reloc 0x00130000 2,548 bytes 2,560 bytes 5.38 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ E25D1B6CA20F80410B2CADBE0AD7192F

Resource Analysis

Total Resources: 1 (381 bytes)
Resource Type Count Total Size Percentage
RT_MANIFEST 1 381 bytes
100%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
29 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware