8090c32b447f955e276ad8f005ea4775
PE Executable | MD5: 8090c32b447f955e276ad8f005ea4775 | Size: 2.18 MB | application/x-dosexec
Symbol Obfuscation Score
|
Hash | Hash Value |
|---|---|
| MD5 | 8090c32b447f955e276ad8f005ea4775
|
| Sha1 | d498af82aba3f8d9be1a5df2bcd07ae5a4011883
|
| Sha256 | 240e2575f20c75c6b5e2ea69bc0f0d9675ffd3fea315ca818bcbee2572ee972f
|
| Sha384 | 2e208086816a6e541110dc510514292203506938b9d7012eabdbced40f66f71a376c43992b5ba5e0fa05883939c4b5b1
|
| Sha512 | e3880ff6cdbc91ad58c0820fe4e400aa9feb9e2d7d32c22ee2e25055b13d62763f8d5d645efcf0034879460e1d189ef7a59fc11d6ee1501461bfc9ea6929dc4d
|
| SSDeep | 49152:DqW07wRPirm2NnPTKKm77LrwCB6uan36z6:DqWjoZNn2Km77LrwkFW
|
| TLSH | FDA5F151B3F5820AF1BF2BB9A47604590773F942AA35E74E098CA1AD1FB37408E507B7
|
PeID
|
Config. Field0 | Value |
|---|---|
| Conf. AES-Salt | BF-EB-1E-56-FB-CD-97-3B-B2-19-02-24-30-A5-78-43-00-3D-56-44-D2-1E-62-B9-D4-F1-80-E7-E6-C3-39-41 |
| Conf. AES-Key | |
| Version | ObjectLength |
| Port | ChainingModeGCM |
| Host | ChainingModeGCM |
| ReconnectDelay | AuthTagLength |
| Key | ChainingMode |
| SubDirectory | KeyDataBlob |
| InstallName | AES |
| Install | Microsoft Primitive Provider |
| Startup | 1 |
| Mutex | 1 |
| StartupKey | -1073700862 |
| HideFile | Ec8lprVX96wl4/96CynH7NhNxYR0rU9jgY6iz1JKDZfm1dLpiLas4sc+86QnevjG0Ocy1FggslBkzOY2+StjNQ== |
| EnableLogger | Z7fC0bQBYrzWTC1zhy38NDIhnFMghJ0/QfH96mo/wa6hZqHJ7lPpC3ihW7GPW2kpVlI+xuNappq7omU5btRbbP6XR1ysYga0uxXJXfLANTM= |
| EncryptionKey | 3000 |
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: ? |
| Module Name | Client.exe |
| Full Name | Client.exe |
| EntryPoint | System.Void krntjnqxudpjebmonyai.1GCgguMpLwLtqUR7pFZY::Main(System.String[]) |
| Scope Name | Client.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Client |
| Assembly Version | 2.6.4.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 2756 |
| Main Method | System.Void krntjnqxudpjebmonyai.1GCgguMpLwLtqUR7pFZY::Main(System.String[]) |
| Main IL Instruction Count | 13 |
| Main IL | ldc.i4 3072 call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType) ldc.i4.2 <null> call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode) call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) call System.Void krntjnqxudpjebmonyai.1GCgguMpLwLtqUR7pFZY::3CjtUe5IHGkuxeEk1v5() call System.Void krntjnqxudpjebmonyai.1GCgguMpLwLtqUR7pFZY::hqcwVkzJodF1() call System.Void krntjnqxudpjebmonyai.1GCgguMpLwLtqUR7pFZY::5cd5sUx1kIKAhgZO() newobj System.Void krntjnqxudpjebmonyai.AllHv13Mvcg::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null> |
| Module Name | Client.exe |
| Full Name | Client.exe |
| EntryPoint | System.Void krntjnqxudpjebmonyai.1GCgguMpLwLtqUR7pFZY::Main(System.String[]) |
| Scope Name | Client.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Client |
| Assembly Version | 2.6.4.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 2756 |
| Main Method | System.Void krntjnqxudpjebmonyai.1GCgguMpLwLtqUR7pFZY::Main(System.String[]) |
| Main IL Instruction Count | 13 |
| Main IL | ldc.i4 3072 call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType) ldc.i4.2 <null> call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode) call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) call System.Void krntjnqxudpjebmonyai.1GCgguMpLwLtqUR7pFZY::3CjtUe5IHGkuxeEk1v5() call System.Void krntjnqxudpjebmonyai.1GCgguMpLwLtqUR7pFZY::hqcwVkzJodF1() call System.Void krntjnqxudpjebmonyai.1GCgguMpLwLtqUR7pFZY::5cd5sUx1kIKAhgZO() newobj System.Void krntjnqxudpjebmonyai.AllHv13Mvcg::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null> |
|
Name0 | Value |
|---|---|
| CnC | ChainingModeGCM |
| Port | ChainingModeGCM |
|
Config. Field0 | Value |
|---|---|
| Conf. AES-Salt | BF-EB-1E-56-FB-CD-97-3B-B2-19-02-24-30-A5-78-43-00-3D-56-44-D2-1E-62-B9-D4-F1-80-E7-E6-C3-39-41 |
| Conf. AES-Key | |
| Version | ObjectLength |
| Port | ChainingModeGCM |
| Host | ChainingModeGCM |
| ReconnectDelay | AuthTagLength |
| Key | ChainingMode |
| SubDirectory | KeyDataBlob |
| InstallName | AES |
| Install | Microsoft Primitive Provider |
| Startup | 1 |
| Mutex | 1 |
| StartupKey | -1073700862 |
| HideFile | Ec8lprVX96wl4/96CynH7NhNxYR0rU9jgY6iz1JKDZfm1dLpiLas4sc+86QnevjG0Ocy1FggslBkzOY2+StjNQ== |
| EnableLogger | Z7fC0bQBYrzWTC1zhy38NDIhnFMghJ0/QfH96mo/wa6hZqHJ7lPpC3ihW7GPW2kpVlI+xuNappq7omU5btRbbP6XR1ysYga0uxXJXfLANTM= |
| EncryptionKey | 3000 |
|
Name0 | Value | Location |
|---|---|---|
| CnC | ChainingModeGCM Malicious |
8090c32b447f955e276ad8f005ea4775 |
| Port | ChainingModeGCM Malicious |
8090c32b447f955e276ad8f005ea4775 |