{"id":8170,"date":"2022-07-30T20:51:59","date_gmt":"2022-07-30T20:51:59","guid":{"rendered":"https:\/\/www.hexacorn.com\/blog\/?p=8170"},"modified":"2022-07-30T20:51:59","modified_gmt":"2022-07-30T20:51:59","slug":"week-of-data-dumps-part-4-games-related-strings","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2022\/07\/30\/week-of-data-dumps-part-4-games-related-strings\/","title":{"rendered":"Week of Data Dumps, Part 4 \u2013 games-related strings"},"content":{"rendered":"\n<p>This series got a bit delayed, because I got sick last week.<\/p>\n\n\n\n<p>&#8212;<\/p>\n\n\n\n<p>This is a bit counter-intuitive &#8211; why would you want to collect strings related to games?<\/p>\n\n\n\n<p>First, there was a time when games were targeted by malware authors a lot. Secondly, if you have a good list of games-related strings, you can quickly classify many samples. If you find these specific strings inside an executable it&#8217;s either a part of a game, or a crack for the game, or a malware targeting a game, or some 3rd party software dealing with games in bulk. Not too many options&#8230; <\/p>\n\n\n\n<p>Today there are many resources listing various game names, their executable names, etc. so instead of giving you the answer on the plate, I will list two decent sources I used in the past:<\/p>\n\n\n\n<ul><li>GameUXLegacyGDFs.dll &#8211; Microsoft library, contains a large database of games inside its resources<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><a href=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2022\/07\/GameUXLegacyGDFs_dll.png\"><img decoding=\"async\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2022\/07\/GameUXLegacyGDFs_dll-1024x177.png\" alt=\"\" class=\"wp-image-8171\" width=\"512\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2022\/07\/GameUXLegacyGDFs_dll-1024x177.png 1024w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2022\/07\/GameUXLegacyGDFs_dll-300x52.png 300w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2022\/07\/GameUXLegacyGDFs_dll-768x133.png 768w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2022\/07\/GameUXLegacyGDFs_dll.png 1244w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<ul><li><a href=\"hxxp:\/\/download-cdn.gfe.nvidia.com\/packages\/DAO\/production\/19252566\/00006CC1\/0.dat\">fingerprint.db<\/a> &#8211; Nvidia&#8217;s file listing many games and collections of file names, and other interesting artifacts<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><a href=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2022\/07\/fingerpring_db.png\"><img decoding=\"async\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2022\/07\/fingerpring_db.png\" alt=\"\" class=\"wp-image-8172\" width=\"512\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2022\/07\/fingerpring_db.png 542w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2022\/07\/fingerpring_db-292x300.png 292w\" sizes=\"(max-width: 542px) 100vw, 542px\" \/><\/a><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>This series got a bit delayed, because I got sick last week. &#8212; This is a bit counter-intuitive &#8211; why would you want to collect strings related to games? First, there was a time when games were targeted by malware &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2022\/07\/30\/week-of-data-dumps-part-4-games-related-strings\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[53,39,21],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/8170"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=8170"}],"version-history":[{"count":3,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/8170\/revisions"}],"predecessor-version":[{"id":8187,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/8170\/revisions\/8187"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=8170"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=8170"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=8170"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}