Suspicious
Suspect

6435bbc81701ef985a7eab6c6ebef559

PE Executable
|
MD5: 6435bbc81701ef985a7eab6c6ebef559
|
Size: 1.77 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
6435bbc81701ef985a7eab6c6ebef559
Sha1
195ebe7179f8f1d65a4f62c621ac3c806b31119a
Sha256
929a6fecc6b43b14b92fb96ea538fc3b64f44a5224e47505bee802817d584e3e
Sha384
268ca047aa21704681dd7bca808d0625f43b6736dbf3ba9b4a6b9ef3eabf3ec26cd0448c9c95ec5da0fe4d944614afd5
Sha512
8d393cefa37caba4dd543a8ed4cc443d3ca878f8dafc9268670324b1ee4e9db7d9694f55515797e318a786e6ff3f1ce1139e0261dc97c940e9f2262b2254ea49
SSDeep
24576:+GeFCw9qOfb2OwK//eu9BrV7qItaERqILw:Veml9U/VVmIR
TLSH
5185D05223D51F58F07F9B396838644147F2BD0BEF25DB8F7E9919CE2860E818661B23

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0032
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
q_9TsXw3Wi1.g.resources
q_9TsXw3Wi1.Resources.resources
675a8bfc004479.Resources.resources
ad8b2c930
[NBF]root.Data
ad8b2c931
[NBF]root.Data
ad8b2c9310
[NBF]root.Data
ad8b2c9311
[NBF]root.Data
ad8b2c9312
[NBF]root.Data
ad8b2c9313
[NBF]root.Data
ad8b2c9314
[NBF]root.Data
ad8b2c9315
[NBF]root.Data
ad8b2c9316
[NBF]root.Data
ad8b2c9317
[NBF]root.Data
ad8b2c9318
[NBF]root.Data
ad8b2c9319
[NBF]root.Data
ad8b2c932
[NBF]root.Data
ad8b2c9320
[NBF]root.Data
ad8b2c9321
[NBF]root.Data
ad8b2c9322
[NBF]root.Data
ad8b2c9323
[NBF]root.Data
ad8b2c9324
[NBF]root.Data
ad8b2c9325
[NBF]root.Data
ad8b2c9326
[NBF]root.Data
ad8b2c9327
[NBF]root.Data
ad8b2c9328
[NBF]root.Data
ad8b2c9329
[NBF]root.Data
ad8b2c933
[NBF]root.Data
ad8b2c9330
[NBF]root.Data
ad8b2c9331
[NBF]root.Data
ad8b2c9332
[NBF]root.Data
ad8b2c9333
[NBF]root.Data
ad8b2c9334
[NBF]root.Data
ad8b2c9335
[NBF]root.Data
ad8b2c9336
[NBF]root.Data
ad8b2c9337
[NBF]root.Data
ad8b2c9338
[NBF]root.Data
ad8b2c9339
[NBF]root.Data
ad8b2c934
[NBF]root.Data
ad8b2c9340
[NBF]root.Data
ad8b2c9341
[NBF]root.Data
ad8b2c9342
[NBF]root.Data
ad8b2c9343
[NBF]root.Data
ad8b2c9344
[NBF]root.Data
ad8b2c9345
[NBF]root.Data
ad8b2c9346
[NBF]root.Data
ad8b2c9347
[NBF]root.Data
ad8b2c9348
[NBF]root.Data
ad8b2c9349
[NBF]root.Data
ad8b2c935
[NBF]root.Data
ad8b2c9350
[NBF]root.Data
ad8b2c9351
[NBF]root.Data
ad8b2c9352
[NBF]root.Data
ad8b2c9353
[NBF]root.Data
ad8b2c9354
[NBF]root.Data
ad8b2c9355
[NBF]root.Data
ad8b2c9356
[NBF]root.Data
ad8b2c9357
[NBF]root.Data
ad8b2c9358
[NBF]root.Data
ad8b2c9359
[NBF]root.Data
ad8b2c936
[NBF]root.Data
ad8b2c9360
[NBF]root.Data
ad8b2c9361
[NBF]root.Data
ad8b2c9362
[NBF]root.Data
ad8b2c9363
[NBF]root.Data
ad8b2c9364
[NBF]root.Data
ad8b2c9365
[NBF]root.Data
ad8b2c937
[NBF]root.Data
ad8b2c938
[NBF]root.Data
ad8b2c939
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

q_9TsXw3Wi1

Full Name

q_9TsXw3Wi1

EntryPoint

System.Void q_9TsXw3Wi1.Dfi34nSzrT9x2::4msYTx8k9reC()

Scope Name

q_9TsXw3Wi1

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

q_9TsXw3Wi1

Assembly Version

2.14.19.228

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1748

Main Method

System.Void q_9TsXw3Wi1.Dfi34nSzrT9x2::4msYTx8k9reC()

Main IL Instruction Count

338

Main IL

nop <null> nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> call System.DateTime System.DateTime::get_Now() stloc.0 <null> ldc.i4 10001 newarr System.Int32 stloc.1 <null> ldloc.1 <null> ldlen <null> conv.i4 <null> ldc.i4.1 <null> sub.ovf <null> stloc.s V_14 ldc.i4.0 <null> stloc.s V_15 br.s IL_003A: ldloc.s V_15 ldloc.1 <null> ldloc.s V_15 ldloc.s V_15 ldc.i4.s 31 mul.ovf <null> ldc.i4 10000 rem <null> stelem.i4 <null> ldloc.s V_15 ldc.i4.1 <null> add.ovf <null> stloc.s V_15 ldloc.s V_15 ldloc.s V_14 ble.s IL_0025: ldloc.1 ldloc.1 <null> call System.Void System.Array::Sort<System.Int32>(System.Int32[]) nop <null> ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr SystemTools ldstr cache.cfg call System.String System.IO.Path::Combine(System.String,System.String,System.String) stloc.2 <null> ldc.r8 24 call System.Double System.Math::Abs(System.Double) call System.Double System.Math::Round(System.Double) conv.ovf.i4 <null> stloc.3 <null> ldloc.3 <null> call System.Object q_9TsXw3Wi1.Dfi34nSzrT9x2/8irNjB7j5xSz.4nzEG::fRy2zp1TcQn(System.Int32) castclass System.Object[] stloc.s V_4 ldstr resources/fencadi.rex ldc.i4.0 <null> newarr System.Object call System.String System.String::Format(System.String,System.Object[]) stloc.s V_5 ldloc.s V_4 ldc.i4.0 <null> ldloc.s V_5 stelem.ref <null> ldloc.s V_4 ldc.i4.2 <null> ldloc.s V_4 ldc.i4.0 <null> ldelem.ref <null> call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object) call System.Byte[] q_9TsXw3Wi1.pm4GKkd/3Tqwdp9DrLo40.yGk6b9F::9zsHod(System.String) stelem.ref <null> call System.String System.IO.Path::GetTempPath() stloc.s V_6 ldloc.s V_6 call System.Boolean System.IO.Directory::Exists(System.String) ldc.i4.0 <null> ceq <null> stloc.s V_16 ldloc.s V_16 brfalse.s IL_00C9: ldc.i4.s 100 ldloc.s V_6 call System.IO.DirectoryInfo System.IO.Directory::CreateDirectory(System.String) pop <null> ldc.i4.s 100 stloc.s V_7 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newobj System.Void System.Int32[0...,0...]::.ctor(System.Int32,System.Int32) stloc.s V_8 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newobj System.Void System.Int32[0...,0...]::.ctor(System.Int32,System.Int32) stloc.s V_9 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newobj System.Void System.Int32[0...,0...]::.ctor(System.Int32,System.Int32) stloc.s V_10 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> stloc.s V_17 ldc.i4.0 <null> stloc.s V_18 br.s IL_014E: ldloc.s V_18 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> stloc.s V_19 ldc.i4.0 <null> stloc.s V_20 br.s IL_0142: ldloc.s V_20 ldloc.s V_8 ldloc.s V_18 ldloc.s V_20 ldloc.s V_18 ldloc.s V_20 add.ovf <null> call System.Void System.Int32[0...,0...]::Set(System.Int32,System.Int32,System.Int32) ldloc.s V_9 ldloc.s V_18 ldloc.s V_20 ldloc.s V_18 ldloc.s V_20 mul.ovf <null> call System.Void System.Int32[0...,0...]::Set(System.Int32,System.Int32,System.Int32) ldloc.s V_20 ldc.i4.1 <null> add.ovf <null> stloc.s V_20 ldloc.s V_20 ldloc.s V_19 ble.s IL_011C: ldloc.s V_8 ldloc.s V_18 ldc.i4.1 <null> add.ovf <null> stloc.s V_18 ldloc.s V_18 ldloc.s V_17 ble.s IL_0111: ldloc.s V_7 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> stloc.s V_21 ldc.i4.0 <null> stloc.s V_22 br.s IL_01C9: ldloc.s V_22 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> stloc.s V_23 ldc.i4.0 <null> stloc.s V_24 br.s IL_01BD: ldloc.s V_24 ldloc.s V_10 ldloc.s V_22 ldloc.s V_24 ldc.i4.0 <null> call System.Void System.Int32[0...,0...]::Set(System.Int32,System.Int32,System.Int32) ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> stloc.s V_25 ldc.i4.0 <null> stloc.s V_26 br.s IL_01B1: ldloc.s V_26 ldloc.s V_10 ldloc.s V_22 ldloc.s V_24 call System.Int32& System.Int32[0...,0...]::Address(System.Int32,System.Int32) dup <null> stloc.s V_27 ldloc.s V_27 ldind.i4 <null> ldloc.s V_8 ldloc.s V_22 ldloc.s V_26 call System.Int32 System.Int32[0...,0...]::Get(System.Int32,System.Int32) ldloc.s V_9 ldloc.s V_26 ldloc.s V_24 call System.Int32 System.Int32[0...,0...]::Get(System.Int32,System.Int32) mul.ovf <null> add.ovf <null> stind.i4 <null> ldloc.s V_26 ldc.i4.1 <null> add.ovf <null> stloc.s V_26 ldloc.s V_26 ldloc.s V_25 ble.s IL_0181: ldloc.s V_10 ldloc.s V_24 ldc.i4.1 <null> add.ovf <null> stloc.s V_24 ldloc.s V_24 ldloc.s V_23 ble.s IL_016A: ldloc.s V_10 ldloc.s V_22 ldc.i4.1 <null> add.ovf <null> stloc.s V_22 ldloc.s V_22 ldloc.s V_21 ble.s IL_015F: ldloc.s V_7 ldloc.s V_4 ldc.i4.3 <null> ldloc.s V_4 ldc.i4.2 <null> ldelem.ref <null> castclass System.Byte[] call System.Byte[] q_9TsXw3Wi1.t_1Hj4/0Lke_a.Md4w7er::ya0Zt6Mo(System.Byte[]) stelem.ref <null> ldloc.s V_10 ldc.i4.s 50 ldc.i4.s 50 call System.Int32 System.Int32[0...,0...]::Get(System.Int32,System.Int32) ldc.i4.s 100 rem <null> conv.r8 <null> ldc.r8 100 div <null> stloc.s V_11 ldloc.s V_11 ldc.r8 0.95 clt <null> stloc.s V_12 ldc.r8 0 stloc.s V_13 ldc.i4.0 <null> stloc.s V_28 ldloc.s V_13 ldc.r8 -1 ldloc.s V_28 conv.r8 <null> call System.Double System.Math::Pow(System.Double,System.Double) ldc.i4.2 <null> ldloc.s V_28 mul.ovf <null> ldc.i4.1 <null> add.ovf <null> conv.r8 <null> div <null> add <null> stloc.s V_13 ldloc.s V_28 ldc.i4.1 <null> add.ovf <null> stloc.s V_28 ldloc.s V_28 ldc.i4 1000000 ble.s IL_0219: ldloc.s V_13 ldloc.s V_13 ldc.r8 4 mul <null> stloc.s V_13 nop <null> ldstr SystemService call System.Boolean System.Diagnostics.EventLog::SourceExists(System.String) stloc.s V_29 ldloc.s V_29 brfalse.s IL_02AA: nop nop <null> ldstr Application newobj System.Void System.Diagnostics.EventLog::.ctor(System.String) stloc.s V_30 ldloc.s V_30 ldstr SystemService callvirt System.Void System.Diagnostics.EventLog::set_Source(System.String) nop <null> ldloc.s V_30 ldstr Module initialized. PI≈{0:F5} ldloc.s V_13 box System.Double call System.String System.String::Format(System.String,System.Object) ldc.i4.4 <null> callvirt System.Void System.Diagnostics.EventLog::WriteEntry(System.String,System.Diagnostics.EventLogEntryType) nop <null> leave.s IL_02A9: nop nop <null> ldloc.s V_30 brfalse.s IL_02A8: endfinally ldloc.s V_30 callvirt System.Void System.IDisposable::Dispose() nop <null> endfinally <null> nop <null> nop <null> leave.s IL_02BA: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_02BA: nop nop <null> ldstr L o a d ldloc.s V_4 ldc.i4.3 <null> ldelem.ref <null> call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) call System.Object q_9TsXw3Wi1.pm4GKkd::7kiDGo4p(System.String,System.Object) pop <null> leave.s IL_02F2: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_31 nop <null> nop <null> leave.s IL_02EA: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_02EA: nop nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_02F2: nop nop <null> ret <null>

Module Name

q_9TsXw3Wi1

Full Name

q_9TsXw3Wi1

EntryPoint

System.Void q_9TsXw3Wi1.Dfi34nSzrT9x2::4msYTx8k9reC()

Scope Name

q_9TsXw3Wi1

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

q_9TsXw3Wi1

Assembly Version

2.14.19.228

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1748

Main Method

System.Void q_9TsXw3Wi1.Dfi34nSzrT9x2::4msYTx8k9reC()

Main IL Instruction Count

338

Main IL

nop <null> nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> call System.DateTime System.DateTime::get_Now() stloc.0 <null> ldc.i4 10001 newarr System.Int32 stloc.1 <null> ldloc.1 <null> ldlen <null> conv.i4 <null> ldc.i4.1 <null> sub.ovf <null> stloc.s V_14 ldc.i4.0 <null> stloc.s V_15 br.s IL_003A: ldloc.s V_15 ldloc.1 <null> ldloc.s V_15 ldloc.s V_15 ldc.i4.s 31 mul.ovf <null> ldc.i4 10000 rem <null> stelem.i4 <null> ldloc.s V_15 ldc.i4.1 <null> add.ovf <null> stloc.s V_15 ldloc.s V_15 ldloc.s V_14 ble.s IL_0025: ldloc.1 ldloc.1 <null> call System.Void System.Array::Sort<System.Int32>(System.Int32[]) nop <null> ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr SystemTools ldstr cache.cfg call System.String System.IO.Path::Combine(System.String,System.String,System.String) stloc.2 <null> ldc.r8 24 call System.Double System.Math::Abs(System.Double) call System.Double System.Math::Round(System.Double) conv.ovf.i4 <null> stloc.3 <null> ldloc.3 <null> call System.Object q_9TsXw3Wi1.Dfi34nSzrT9x2/8irNjB7j5xSz.4nzEG::fRy2zp1TcQn(System.Int32) castclass System.Object[] stloc.s V_4 ldstr resources/fencadi.rex ldc.i4.0 <null> newarr System.Object call System.String System.String::Format(System.String,System.Object[]) stloc.s V_5 ldloc.s V_4 ldc.i4.0 <null> ldloc.s V_5 stelem.ref <null> ldloc.s V_4 ldc.i4.2 <null> ldloc.s V_4 ldc.i4.0 <null> ldelem.ref <null> call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object) call System.Byte[] q_9TsXw3Wi1.pm4GKkd/3Tqwdp9DrLo40.yGk6b9F::9zsHod(System.String) stelem.ref <null> call System.String System.IO.Path::GetTempPath() stloc.s V_6 ldloc.s V_6 call System.Boolean System.IO.Directory::Exists(System.String) ldc.i4.0 <null> ceq <null> stloc.s V_16 ldloc.s V_16 brfalse.s IL_00C9: ldc.i4.s 100 ldloc.s V_6 call System.IO.DirectoryInfo System.IO.Directory::CreateDirectory(System.String) pop <null> ldc.i4.s 100 stloc.s V_7 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newobj System.Void System.Int32[0...,0...]::.ctor(System.Int32,System.Int32) stloc.s V_8 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newobj System.Void System.Int32[0...,0...]::.ctor(System.Int32,System.Int32) stloc.s V_9 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newobj System.Void System.Int32[0...,0...]::.ctor(System.Int32,System.Int32) stloc.s V_10 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> stloc.s V_17 ldc.i4.0 <null> stloc.s V_18 br.s IL_014E: ldloc.s V_18 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> stloc.s V_19 ldc.i4.0 <null> stloc.s V_20 br.s IL_0142: ldloc.s V_20 ldloc.s V_8 ldloc.s V_18 ldloc.s V_20 ldloc.s V_18 ldloc.s V_20 add.ovf <null> call System.Void System.Int32[0...,0...]::Set(System.Int32,System.Int32,System.Int32) ldloc.s V_9 ldloc.s V_18 ldloc.s V_20 ldloc.s V_18 ldloc.s V_20 mul.ovf <null> call System.Void System.Int32[0...,0...]::Set(System.Int32,System.Int32,System.Int32) ldloc.s V_20 ldc.i4.1 <null> add.ovf <null> stloc.s V_20 ldloc.s V_20 ldloc.s V_19 ble.s IL_011C: ldloc.s V_8 ldloc.s V_18 ldc.i4.1 <null> add.ovf <null> stloc.s V_18 ldloc.s V_18 ldloc.s V_17 ble.s IL_0111: ldloc.s V_7 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> stloc.s V_21 ldc.i4.0 <null> stloc.s V_22 br.s IL_01C9: ldloc.s V_22 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> stloc.s V_23 ldc.i4.0 <null> stloc.s V_24 br.s IL_01BD: ldloc.s V_24 ldloc.s V_10 ldloc.s V_22 ldloc.s V_24 ldc.i4.0 <null> call System.Void System.Int32[0...,0...]::Set(System.Int32,System.Int32,System.Int32) ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> stloc.s V_25 ldc.i4.0 <null> stloc.s V_26 br.s IL_01B1: ldloc.s V_26 ldloc.s V_10 ldloc.s V_22 ldloc.s V_24 call System.Int32& System.Int32[0...,0...]::Address(System.Int32,System.Int32) dup <null> stloc.s V_27 ldloc.s V_27 ldind.i4 <null> ldloc.s V_8 ldloc.s V_22 ldloc.s V_26 call System.Int32 System.Int32[0...,0...]::Get(System.Int32,System.Int32) ldloc.s V_9 ldloc.s V_26 ldloc.s V_24 call System.Int32 System.Int32[0...,0...]::Get(System.Int32,System.Int32) mul.ovf <null> add.ovf <null> stind.i4 <null> ldloc.s V_26 ldc.i4.1 <null> add.ovf <null> stloc.s V_26 ldloc.s V_26 ldloc.s V_25 ble.s IL_0181: ldloc.s V_10 ldloc.s V_24 ldc.i4.1 <null> add.ovf <null> stloc.s V_24 ldloc.s V_24 ldloc.s V_23 ble.s IL_016A: ldloc.s V_10 ldloc.s V_22 ldc.i4.1 <null> add.ovf <null> stloc.s V_22 ldloc.s V_22 ldloc.s V_21 ble.s IL_015F: ldloc.s V_7 ldloc.s V_4 ldc.i4.3 <null> ldloc.s V_4 ldc.i4.2 <null> ldelem.ref <null> castclass System.Byte[] call System.Byte[] q_9TsXw3Wi1.t_1Hj4/0Lke_a.Md4w7er::ya0Zt6Mo(System.Byte[]) stelem.ref <null> ldloc.s V_10 ldc.i4.s 50 ldc.i4.s 50 call System.Int32 System.Int32[0...,0...]::Get(System.Int32,System.Int32) ldc.i4.s 100 rem <null> conv.r8 <null> ldc.r8 100 div <null> stloc.s V_11 ldloc.s V_11 ldc.r8 0.95 clt <null> stloc.s V_12 ldc.r8 0 stloc.s V_13 ldc.i4.0 <null> stloc.s V_28 ldloc.s V_13 ldc.r8 -1 ldloc.s V_28 conv.r8 <null> call System.Double System.Math::Pow(System.Double,System.Double) ldc.i4.2 <null> ldloc.s V_28 mul.ovf <null> ldc.i4.1 <null> add.ovf <null> conv.r8 <null> div <null> add <null> stloc.s V_13 ldloc.s V_28 ldc.i4.1 <null> add.ovf <null> stloc.s V_28 ldloc.s V_28 ldc.i4 1000000 ble.s IL_0219: ldloc.s V_13 ldloc.s V_13 ldc.r8 4 mul <null> stloc.s V_13 nop <null> ldstr SystemService call System.Boolean System.Diagnostics.EventLog::SourceExists(System.String) stloc.s V_29 ldloc.s V_29 brfalse.s IL_02AA: nop nop <null> ldstr Application newobj System.Void System.Diagnostics.EventLog::.ctor(System.String) stloc.s V_30 ldloc.s V_30 ldstr SystemService callvirt System.Void System.Diagnostics.EventLog::set_Source(System.String) nop <null> ldloc.s V_30 ldstr Module initialized. PI≈{0:F5} ldloc.s V_13 box System.Double call System.String System.String::Format(System.String,System.Object) ldc.i4.4 <null> callvirt System.Void System.Diagnostics.EventLog::WriteEntry(System.String,System.Diagnostics.EventLogEntryType) nop <null> leave.s IL_02A9: nop nop <null> ldloc.s V_30 brfalse.s IL_02A8: endfinally ldloc.s V_30 callvirt System.Void System.IDisposable::Dispose() nop <null> endfinally <null> nop <null> nop <null> leave.s IL_02BA: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_02BA: nop nop <null> ldstr L o a d ldloc.s V_4 ldc.i4.3 <null> ldelem.ref <null> call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) call System.Object q_9TsXw3Wi1.pm4GKkd::7kiDGo4p(System.String,System.Object) pop <null> leave.s IL_02F2: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_31 nop <null> nop <null> leave.s IL_02EA: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_02EA: nop nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_02F2: nop nop <null> ret <null>

6435bbc81701ef985a7eab6c6ebef559 (1.77 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0032
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
q_9TsXw3Wi1.g.resources
q_9TsXw3Wi1.Resources.resources
675a8bfc004479.Resources.resources
ad8b2c930
[NBF]root.Data
ad8b2c931
[NBF]root.Data
ad8b2c9310
[NBF]root.Data
ad8b2c9311
[NBF]root.Data
ad8b2c9312
[NBF]root.Data
ad8b2c9313
[NBF]root.Data
ad8b2c9314
[NBF]root.Data
ad8b2c9315
[NBF]root.Data
ad8b2c9316
[NBF]root.Data
ad8b2c9317
[NBF]root.Data
ad8b2c9318
[NBF]root.Data
ad8b2c9319
[NBF]root.Data
ad8b2c932
[NBF]root.Data
ad8b2c9320
[NBF]root.Data
ad8b2c9321
[NBF]root.Data
ad8b2c9322
[NBF]root.Data
ad8b2c9323
[NBF]root.Data
ad8b2c9324
[NBF]root.Data
ad8b2c9325
[NBF]root.Data
ad8b2c9326
[NBF]root.Data
ad8b2c9327
[NBF]root.Data
ad8b2c9328
[NBF]root.Data
ad8b2c9329
[NBF]root.Data
ad8b2c933
[NBF]root.Data
ad8b2c9330
[NBF]root.Data
ad8b2c9331
[NBF]root.Data
ad8b2c9332
[NBF]root.Data
ad8b2c9333
[NBF]root.Data
ad8b2c9334
[NBF]root.Data
ad8b2c9335
[NBF]root.Data
ad8b2c9336
[NBF]root.Data
ad8b2c9337
[NBF]root.Data
ad8b2c9338
[NBF]root.Data
ad8b2c9339
[NBF]root.Data
ad8b2c934
[NBF]root.Data
ad8b2c9340
[NBF]root.Data
ad8b2c9341
[NBF]root.Data
ad8b2c9342
[NBF]root.Data
ad8b2c9343
[NBF]root.Data
ad8b2c9344
[NBF]root.Data
ad8b2c9345
[NBF]root.Data
ad8b2c9346
[NBF]root.Data
ad8b2c9347
[NBF]root.Data
ad8b2c9348
[NBF]root.Data
ad8b2c9349
[NBF]root.Data
ad8b2c935
[NBF]root.Data
ad8b2c9350
[NBF]root.Data
ad8b2c9351
[NBF]root.Data
ad8b2c9352
[NBF]root.Data
ad8b2c9353
[NBF]root.Data
ad8b2c9354
[NBF]root.Data
ad8b2c9355
[NBF]root.Data
ad8b2c9356
[NBF]root.Data
ad8b2c9357
[NBF]root.Data
ad8b2c9358
[NBF]root.Data
ad8b2c9359
[NBF]root.Data
ad8b2c936
[NBF]root.Data
ad8b2c9360
[NBF]root.Data
ad8b2c9361
[NBF]root.Data
ad8b2c9362
[NBF]root.Data
ad8b2c9363
[NBF]root.Data
ad8b2c9364
[NBF]root.Data
ad8b2c9365
[NBF]root.Data
ad8b2c937
[NBF]root.Data
ad8b2c938
[NBF]root.Data
ad8b2c939
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙