Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5:
Size: 0 B
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PearlClient.Connection.Handle_Packets.RemoteChatHandler.resources
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\byt3d4sh\Desktop\Projects\PearlProject\PearlClient\obj\x64\Debug\PearlClient.pdb
Module Name
PearlClient.exe
Full Name
PearlClient.exe
EntryPoint
System.Void PearlClient.Program::Main()
Scope Name
PearlClient.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
PearlClient
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
2579
Main Method
System.Void PearlClient.Program::Main()
Main IL Instruction Count
220
Main IL
call System.Boolean PearlClient.Helper.MutexControl::CreateMutex()
brtrue.s IL_0012: ldsfld System.String PearlClient.Config.Settings::ProcessKiller
call System.Void PearlClient.Helper.Methods::ClientOnExit()
ldc.i4.1 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String PearlClient.Config.Settings::ProcessKiller
ldstr True
call System.Boolean System.String::op_Equality(System.String,System.String)
brfalse.s IL_0040: ldsfld System.String PearlClient.Config.Settings::DefenderExclusion
ldnull <null>
ldftn System.Void PearlClient.Helper.ProcessKiller::Start()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
dup <null>
ldc.i4.1 <null>
callvirt System.Void System.Threading.Thread::set_IsBackground(System.Boolean)
callvirt System.Void System.Threading.Thread::Start()
ldsfld System.String PearlClient.Config.Settings::DefenderExclusion
ldstr True
call System.Boolean System.String::op_Equality(System.String,System.String)
brfalse.s IL_005D: call System.Boolean PearlClient.Helper.EnvironmentCheck::IsEnvironmentSafe()
call System.Boolean PearlClient.Helper.ClientInformation::GetPrivileges()
brfalse.s IL_005D: call System.Boolean PearlClient.Helper.EnvironmentCheck::IsEnvironmentSafe()
call System.Void PearlClient.Helper.Policies::ExcludeDefender()
call System.Boolean PearlClient.Helper.EnvironmentCheck::IsEnvironmentSafe()
brtrue.s IL_006F: ldsfld System.String PearlClient.Config.Settings::CountryBlacklist
call System.Void PearlClient.Helper.Methods::ClientOnExit()
ldc.i4.1 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String PearlClient.Config.Settings::CountryBlacklist
ldstr True
call System.Boolean System.String::op_Equality(System.String,System.String)
brfalse.s IL_00C6: ldsfld System.String PearlClient.Config.Settings::DisableInstallPrompt
ldsfld System.String PearlClient.Config.Settings::BlacklistedCountries
ldc.i4.1 <null>
newarr System.Char
dup <null>
ldc.i4.0 <null>
ldc.i4.s 59
stelem.i2 <null>
callvirt System.String[] System.String::Split(System.Char[])
ldsfld System.Func`2<System.String,System.Boolean> PearlClient.Program/<>c::<>9__0_0
dup <null>
brtrue.s IL_00B4: call System.Boolean System.Linq.Enumerable::Any<System.String>(System.Collections.Generic.IEnumerable`1<System.String>,System.Func`2<System.String,System.Boolean>)
pop <null>
ldsfld PearlClient.Program/<>c PearlClient.Program/<>c::<>9
ldftn System.Boolean PearlClient.Program/<>c::<Main>b__0_0(System.String)
newobj System.Void System.Func`2<System.String,System.Boolean>::.ctor(System.Object,System.IntPtr)
dup <null>
stsfld System.Func`2<System.String,System.Boolean> PearlClient.Program/<>c::<>9__0_0
call System.Boolean System.Linq.Enumerable::Any<System.String>(System.Collections.Generic.IEnumerable`1<System.String>,System.Func`2<System.String,System.Boolean>)
brfalse.s IL_00C6: ldsfld System.String PearlClient.Config.Settings::DisableInstallPrompt
call System.Void PearlClient.Helper.Methods::ClientOnExit()
ldc.i4.1 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String PearlClient.Config.Settings::DisableInstallPrompt
ldstr False
call System.Boolean System.String::op_Equality(System.String,System.String)
brfalse.s IL_00FF: call System.Boolean PearlClient.Helper.ClientInformation::GetPrivileges()
ldstr Pearl is a Remote Administration Tool for Windows. It allows the administrator to make changes to system remotely. You should only install this client from sources you trust.
ldstr Install Pearl
ldc.i4.4 <null>
ldc.i4.s 64
ldc.i4.0 <null>
ldc.i4 2097152
call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon,System.Windows.Forms.MessageBoxDefaultButton,System.Windows.Forms.MessageBoxOptions)
stloc.1 <null>
ldloc.1 <null>
ldc.i4.6 <null>
beq.s IL_00FF: call System.Boolean PearlClient.Helper.ClientInformation::GetPrivileges()
call System.Void PearlClient.Helper.Methods::ClientOnExit()
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Boolean PearlClient.Helper.ClientInformation::GetPrivileges()
brtrue IL_01A6: ldsfld System.String PearlClient.Config.Settings::InstallClient
ldsfld System.String PearlClient.Config.Settings::ForceAdmin
ldstr True
call System.Boolean System.String::op_Equality(System.String,System.String)
brfalse IL_01A6: ldsfld System.String PearlClient.Config.Settings::InstallClient
call System.Void PearlClient.Helper.Methods::ClientOnExit()
call System.String System.Environment::get_SystemDirectory()
ldstr cmd.exe
call System.String System.IO.Path::Combine(System.String,System.String)
stloc.2 <null>
nop <null>
newobj System.Void System.Diagnostics.ProcessStartInfo::.ctor()
dup <null>
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_UseShellExecute(System.Boolean)
dup <null>
call System.String System.Environment::get_CurrentDirectory()
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_WorkingDirectory(System.String)
dup <null>
ldloc.2 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_FileName(System.String)
dup <null>
ldstr /c "
call System.Diagnostics.Process System.Diagnostics.Process::GetCurrentProcess()
callvirt System.Diagnostics.ProcessModule System.Diagnostics.Process::get_MainModule()
callvirt System.String System.Diagnostics.ProcessModule::get_FileName()
ldstr "
call System.String System.String::Concat(System.String,System.String,System.String)
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_Arguments(System.String)
dup <null>
ldstr runas
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_Verb(System.String)
dup <null>
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_CreateNoWindow(System.Boolean)
dup <null>
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_WindowStyle(System.Diagnostics.ProcessWindowStyle)
stloc.3 <null>
call System.Void PearlClient.Helper.Methods::ClientOnExit()
ldloc.3 <null>
call System.Diagnostics.Process System.Diagnostics.Process::Start(System.Diagnostics.ProcessStartInfo)
pop <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
leave.s IL_0132: nop
pop <null>
leave.s IL_0132: nop
ldsfld System.String PearlClient.Config.Settings::InstallClient
ldstr True
call System.Boolean System.String::op_Equality(System.String,System.String)
brfalse.s IL_01BC: ldsfld System.String PearlClient.Config.Settings::Botkiller
call System.Void PearlClient.Setup.ClientInstaller::Install()
ldsfld System.String PearlClient.Config.Settings::Botkiller
ldstr True
call System.Boolean System.String::op_Equality(System.String,System.String)
brfalse.s IL_01EA: ldsfld Microsoft.Win32.RegistryKey Microsoft.Win32.Registry::CurrentUser
ldnull <null>
ldftn System.Void PearlClient.Helper.Botkiller::Start()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
dup <null>
ldc.i4.1 <null>
callvirt System.Void System.Threading.Thread::set_IsBackground(System.Boolean)
callvirt System.Void System.Threading.Thread::Start()
ldsfld Microsoft.Win32.RegistryKey Microsoft.Win32.Registry::CurrentUser
ldstr Software\Pearl\WinLocker
callvirt Microsoft.Win32.RegistryKey Microsoft.Win32.RegistryKey::OpenSubKey(System.String)
stloc.s V_4
ldloc.s V_4
brfalse IL_0289: leave.s IL_0297
ldloc.s V_4
ldstr Autostart
ldc.i4.0 <null>
box System.Int32
callvirt System.Object Microsoft.Win32.RegistryKey::GetValue(System.String,System.Object)
unbox.any System.Int32
stloc.s V_5
ldloc.s V_5
ldc.i4.1 <null>
bne.un.s IL_0289: leave.s IL_0297
ldloc.s V_4
ldstr Attempts
ldc.i4.0 <null>
box System.Int32
callvirt System.Object Microsoft.Win32.RegistryKey::GetValue(System.String,System.Object)
unbox.any System.Int32
stloc.s V_6
ldloc.s V_4
ldstr Password
ldc.i4.0 <null>
box System.Int32
callvirt System.Object Microsoft.Win32.RegistryKey::GetValue(System.String,System.Object)
unbox.any System.Int32
stloc.s V_7
ldloc.s V_4
ldstr ReasonForBlocking
ldstr 
callvirt System.Object Microsoft.Win32.RegistryKey::GetValue(System.String,System.Object)
castclass System.String
stloc.s V_8
ldstr DoWinLocker:{0}:{1}:{2}
ldloc.s V_6
box System.Int32
ldloc.s V_7
box System.Int32
ldloc.s V_8
call System.String System.String::Format(System.String,System.Object,System.Object,System.Object)
call System.Void PearlClient.Connection.Handle_Packets.WinLockerHandler::Start(System.String)
leave.s IL_0297: ldsfld Microsoft.Win32.RegistryKey Microsoft.Win32.Registry::CurrentUser
ldloc.s V_4
brfalse.s IL_0296: endfinally
ldloc.s V_4
callvirt System.Void System.IDisposable::Dispose()
endfinally <null>
ldsfld Microsoft.Win32.RegistryKey Microsoft.Win32.Registry::CurrentUser
ldstr Software\Pearl\Note
callvirt Microsoft.Win32.RegistryKey Microsoft.Win32.RegistryKey::OpenSubKey(System.String)
stloc.s V_9
ldloc.s V_9
brfalse.s IL_02C2: leave.s IL_02D0
ldloc.s V_9
ldstr Note
callvirt System.Object Microsoft.Win32.RegistryKey::GetValue(System.String)
callvirt System.String System.Object::ToString()
stsfld System.String PearlClient.Config.Settings::Note
leave.s IL_02D0: call System.Void PearlClient.Helper.PluginManager::Initialize()
ldloc.s V_9
brfalse.s IL_02CF: endfinally
ldloc.s V_9
callvirt System.Void System.IDisposable::Dispose()
endfinally <null>
call System.Void PearlClient.Helper.PluginManager::Initialize()
call System.Void PearlClient.Setup.AdvancedInstaller::Install()
newobj System.Void PearlClient.Connection.Client::.ctor()
stloc.0 <null>
ldloc.0 <null>
callvirt System.Threading.Tasks.Task PearlClient.Connection.Client::ConnectAsync()
callvirt System.Runtime.CompilerServices.TaskAwaiter System.Threading.Tasks.Task::GetAwaiter()
stloc.s V_10
ldloca.s V_10
call System.Void System.Runtime.CompilerServices.TaskAwaiter::GetResult()
leave.s IL_02F9: ret
pop <null>
leave.s IL_02F9: ret
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙