Symbol Ofbuscation Score
|
Hash | Hash Value |
|---|---|
| MD5 | 6c856327dcb9f8c341c601867b1622c5
|
| Sha1 | 400aaf77497d3e4fc6fc347ac8e8df83367600c5
|
| Sha256 | 7f93c05e8f0a7c6c4e6ee7f82da40e66e9aa2191ad87da82da2b0c478a6dac97
|
| Sha384 | ae36a0da12068162e52fbb57c3adbc9854b03b3eefd86761ce7bced7f10cb6f37a88f1d3db57f59dc86a69e82ebd3dc2
|
| Sha512 | b595025d82b9205b61d9c00f2cc4dfad5accb9ab5511491c0e25afce47675fffb76c0ad6aae09590e5b70ab65992e196e0764bda1b97c0ef4c204e3b951dbcc9
|
| SSDeep | 3072:OcZqf7D342p/0+mAckyQWzwQ0gMwB1fA0PuTVAtkxzf3RRbUgQp:OcZqf7DIOnaDxB1fA0GTV8kpbUZ
|
| TLSH | 60147C5823E8C614EE7F4B75D4A1124597F0F163F947EB0B4FC894AA2D23740EA60AB7
|
PeID
|
Config. Field0 | Value |
|---|---|
| [Configuration Module Name] | Arguments |
| [Configuration Module Full Name] | Arguments |
| IP | ADEvVTUoLhw+DlEeKRMlGA== |
| ID | Gy0sEB0aIQUQISsTPy42Aw== |
| Message | |
| Key | MeffyBois |
| Version | 0 |
|
Config. Field0 | Value |
|---|---|
| [Configuration Module Name] | Arguments |
| [Configuration Module Full Name] | Arguments |
| IP (C2) | 127.0.0.1:80 |
| ID | TrouserSnake |
| Key | MeffyBois |
| Version | 0 |
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Authenticode present at 0x2EC00 size 10408 bytes |
| Module Name | Steanings.exe |
| Full Name | Steanings.exe |
| EntryPoint | System.Void Program::Main() |
| Scope Name | Steanings.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Steanings |
| Assembly Version | 1.1.21.1 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 301 |
| Main Method | System.Void Program::Main() |
| Main IL Instruction Count | 17 |
| Main IL | nop <null> nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void Form1::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> nop <null> leave.s IL_0022: ret stloc.0 <null> nop <null> nop <null> leave.s IL_0022: ret ret <null> |
| Module Name | Steanings.exe |
| Full Name | Steanings.exe |
| EntryPoint | System.Void Program::Main() |
| Scope Name | Steanings.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Steanings |
| Assembly Version | 1.1.21.1 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 301 |
| Main Method | System.Void Program::Main() |
| Main IL Instruction Count | 17 |
| Main IL | nop <null> nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void Form1::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> nop <null> leave.s IL_0022: ret stloc.0 <null> nop <null> nop <null> leave.s IL_0022: ret ret <null> |
|
Config. Field0 | Value |
|---|---|
| [Configuration Module Name] | Arguments |
| [Configuration Module Full Name] | Arguments |
| IP | ADEvVTUoLhw+DlEeKRMlGA== |
| ID | Gy0sEB0aIQUQISsTPy42Aw== |
| Message | |
| Key | MeffyBois |
| Version | 0 |
|
Config. Field0 | Value |
|---|---|
| [Configuration Module Name] | Arguments |
| [Configuration Module Full Name] | Arguments |
| IP (C2) | 127.0.0.1:80 |
| ID | TrouserSnake |
| Key | MeffyBois |
| Version | 0 |