The version dll (Steamworks DLC unlocker) acidicoala ʕ •ᴥ•ʔ File Malware Analysis
Gridinsoft Logo

The version.dll (Steamworks DLC unlocker) File Analysis

Technical Analysis

File Name version.dll
File Type
Win32 DLL
Magic Bytes PE32+ executable (DLL) (console) x86-64, for MS Windows
SSDEEP Hash
49152:H46lee+N9HaIHykNol2Q5WCfiJ9PHndduoL12v2SArN5Sz0XsSo2VVTzJBu4zq6d:qHnM2Q5WCfiJ9PWHLgTzJuuhn
Scanner Version 1.0.224.174
Database Version 2025-09-04 18:00:29 UTC

Suspicious File Detected

Detected by 27 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
38%
Detection Rate
7,911,936
File Size (bytes)
27/72
Engines Detected
2025-09-04
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
2211ff2a12eb1580212dccd5e1e4b513
SHA1
e1e659a659f6b03ae8629fb1820a2dda19bb0e87
SHA256
7b269ece82fe5216804784de4bca6370b9c3b5e749c75deedb0f395b1fb7ff49
SHA512
68e08a95025fcd03002548775ff3ff812a8a2f4e28f93530bf58dabba81114b924eb8668fc08c95abe972b09e2c335b96f6a0ada7e7050b8175cd5aac0d6c956
ImpHash
8b8c90ad05a5af374379c55041cf307b

Security Engines with Detections (27 of 72)

Cynet
Malicious (score: 99) Malicious
CTX
dll.trojan.agen Malicious
VIPRE
Trojan.GenericKD.77232547 Malicious
Symantec
ML.Attribute.HighConfidence Malicious
Elastic
malicious (high confidence) Malicious
ESET-NOD32
a variant of Win64/Agent_AGen.GOJ Malicious
BitDefender
Trojan.GenericKD.77232547 Malicious
MicroWorld-eScan
Trojan.GenericKD.77232547 Malicious
Avast
Win64:MalwareX-gen [Bd] Malicious
Emsisoft
Trojan.GenericKD.77232547 (B) Malicious
F-Secure
Trojan.TR/Agent_AGen.hwjpx Malicious
McAfeeD
ti!7B269ECE82FE Malicious
Sophos
Mal/Generic-S Malicious
Ikarus
Win32.Outbreak Malicious
Google
Detected Malicious
Avira
TR/Agent_AGen.hwjpx Malicious
Microsoft
Trojan:Win32/Wacatac.B!ml Malicious
Arcabit
Trojan.Generic.D49A79A3 Malicious
GData
Trojan.GenericKD.77232547 Malicious
Varist
W64/ABTrojan.OZGS-1152 Malicious
TrendMicro-HouseCall
TROJ_GEN.R002H09I325 Malicious
Rising
Trojan.Agent!8.B1E (LESS:bWQ1Oi1660Hr9CfH) Malicious
TrellixENS
Artemis!2211FF2A12EB Malicious
Fortinet
W64/Agent_AGen.GOJ!tr Malicious
AVG
Win64:MalwareX-gen [Bd] Malicious
DeepInstinct
MALICIOUS Malicious
alibabacloud
Trojan:Win/Agent_AGen.GPU Malicious
45 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Image Base 0x180000000
Entry Point 0x1801d7838
Compilation Time 2025-08-31 19:28:42
Checksum 0x00000000 (Actual: 0x00796876)
OS Version 6.0
PEiD Signatures PE32+ executable (DLL) (console) x86-64, for MS Windows
PDB Path D:\a\SmokeAPI\SmokeAPI\build\64\SmokeAPI\Release\steam_api64.pdb
Digital Signature No valid SignedData structure was found.
Imports 8 libraries
WS2_32, bcrypt, ADVAPI32, CRYPT32, KERNEL32, USER32, SHELL32, VERSION
Exports 1539 functions
Resources 2 Resources
Sections 7 Sections

Version Information

CompanyName acidicoala ʕ •ᴥ•ʔ
FileDescription Steamworks DLC unlocker
FileVersion 3.1.0
InternalName SmokeAPI
LegalCopyright Fuck the copyright \ud83d\udd95
OriginalFilename SmokeAPI.dll
ProductName SmokeAPI
ProductVersion 3.1.0
Translation 0x0409 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 2,887,052 bytes 2,887,168 bytes 6.46 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 3FF5363113A483645A4737BC3FB379FB
.rdata 0x002c2000 4,805,738 bytes 4,806,144 bytes 3.98 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 034605906E924F28186E214A626E4E7E
.data 0x00758000 75,948 bytes 62,976 bytes 5.06 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE C677E46E0A0574E55703F2FBAFD285F0
.pdata 0x0076b000 137,088 bytes 137,216 bytes 6.39 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 9FF27E93E31CB4855A0F1C3DCA4FCB54
.fptable 0x0078d000 256 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BF619EAC0CDF3F68D496EA9344137E8B
.rsrc 0x0078e000 1,264 bytes 1,536 bytes 3.70 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 03CEC06A4C5A8E826AD6A4C7508105BE
.reloc 0x0078f000 15,168 bytes 15,360 bytes 6.10 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 3958888D8E5B3D4C512B8A1E9F23F192

Resource Analysis

Total Resources: 2 (1,101 bytes)
Resource Type Count Total Size Percentage
RT_VERSION 1 720 bytes
65.4%
RT_MANIFEST 1 381 bytes
34.6%

Certificate Chain Analysis

Certificate Information
Product SmokeAPI
Description Steamworks DLC unlocker
File Version 3.1.0
Original Name SmokeAPI.dll
Internal Name SmokeAPI
Copyright Fuck the copyright 🖕

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
27 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware