Symbol Ofbuscation Score
Hash | Hash Value |
---|---|
MD5 | 885127590b2c7ec029e1c5aab5d0635a
|
Sha1 | a74100abab8962b0cdc97bedb9399180443c0f3e
|
Sha256 | 8e1f62b87234e54baf7ca40bfd2a81a6ed53b5a009b15ce7e4cba7d54d39a3a2
|
Sha384 | 413a7fdb68ee7e011db1258d9d90d2a2a7f13ea14c78cad3c7bb326d073a44f012d8ba7438ed48a546471c15f8f3db9d
|
Sha512 | f02a426b3cc22325633f2d02b5fac09a330e775404092274258b824f24f09df4c61645cb6591e32d163536d1f750b6974310e9b8273e545ea8e07e0aa0e73443
|
SSDeep | 1536:FmIm86tX2kNff4sKu+UYFDGXw5bfAPGBKB4ic/drQTGZx:Fm986tmkN7Ku+UYFDGXw5bfKBLc/dGix
|
TLSH | E453F7013BE98029F3BE8F7469F7628546F9F5AB2D12C55D1CC550CE0932B829A41BFB
|
PeID
Config. Field0 | Value |
---|---|
Key (AES_256) | bGlMMVRvamlOcFFEOGN2Mkpsc2VxSWZCMUdDbHNJR3Y= |
Pastebin | - |
Certificate | MIIE8jCCAtqgAwIBAgIQAOQb7nA/hP/L1XXxqdDJNzANBgkqhkiG9w0BAQ0FADAaMRgwFgYDVQQDDA9Bc3luY1JBVCBTZXJ2ZXIwIBcNMjMwNTI1MDUyMTIyWhgPOTk5OTEyMzEyMzU5NTlaMBoxGDAWBgNVBAMMD0FzeW5jUkFUIFNlcnZlcjCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAIykAVxs0s6rZ/dwP6ujJtpnj6RSsCsZN6Cfj1InZxSIswX+zNiKJys8xyLlyexoya3ebLp5gOSzNvGMlxluLm9vCaayOzt8HuaCCUFntv/AIiigkbE2gqVYjh7qdObXhyhAgjuygHDP0QCc+VzP1aVH4CesUy1gGvxgOgmdXok2AjCssH69OYGA/DAdEzaOK7TtFqS2qqCzCldLuNBa2xy0/Yb73Zko42hlx+hvp/ciTNyFDXqIBdUIu/6X3on+ecdW8SiLMjzr8Xf1BHcoVgTbDto7EpNq2a1b2CjI23YMlc+mRq33k6R2Dw0NNZmNdnTjnFFVmZZ419g2qIxR+JetlOui7Lc77pKX5Om0+HBZqQYKTCxMVykxz0G7EuAxIXG01Wlogv1Ulj31UH2APYQpgRyZ2DUhqJ1Ls3MLxd3X4UJ00DLnhOQf4bSxqZityJ+17tFLj/qSw8niWYm9lzor2652DmCyw2tFMOnkrnBStNaymtyE5JiN3hZ+3xLlCShjHbR6ANpnmPJJWyUnVLHzYj9Fg5cVrfcIHfGDxkh6P/x32CuG1uzxFS0NsZIG6dsiNmBJLZ/B+JQp2V5a1ux3bwzlgEd3OYdDAf8KzXjFmnhfLqhBN/e33eAYdLtZ5ijj9VTACHiEA73NNTROv+9MrHe+jlDqDX+JFS2HTRktAgMBAAGjMjAwMB0GA1UdDgQWBBSGuCNUrBGiR5cyCuX6uVeVEgA8yDAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBDQUAA4ICAQBBMeYWK/JJKSBUsQ4Ba2RHStyT+uunyfCP9ht58sDUygZWxFQxl4Tmw1JLTRjU2FNia9d73P3k7BuDux/zSWJy0rc+Yr5H174M86L7rXyM/dhyZ26Ansn3rxNG7OJP+UQh559z7wwa5sVstFlVyAZOYFBUGGGMhCK/odXhRgJxnWwPR5LKzbQKGXNsvYfnyjWsh65631ZSMvoH3eblBluOwhvCHP7MotRPD8xkmMfIL9npMprJRPHco5MnenLv9c1R6x7AS93fEh359l3fOdL1LTU5K7Q0FydPztV19HDkJyotROS1hOiWze1LNQLXQ6701jb20bIcxeeWyfzJSew1p6j/iIvbBBEKoeQVx6gCXN2UHfZRzeoQKzWQPJ9EDaobDIZ6VyBJ3Vg2zCuFtLL73oJzycow0Rudn/2O9FHy6rucrLcyWxi4AiH+a0b2l1GwvZ/46TUdGFvygMflzdSxf/sVeCrYOTxXJBAnCyz1Yx5hcFI/lblBL70necTt0FDnwHQSWyrdouWYWlGupZ9HUKg6IpGEg9tx0mwyvIycHXTeeQ+NVHYR+WmbVcgYy5HIMPPOyAV7FVCjvRfQ9GofgzRasjDKSqMeWChkMC2zMjI6j6WzWDK5ZD6mCcTiP5P0f3tOkYV/+cw2elMNBmmDAnZVPwweENRxZ/YelFug7Q== |
ServerSignature | RzLYst500hncDWwVOCXGSYphAQJEGhQIteg8UXWmArkDswJnvvdK43oU+/eIi4uNkQb1Pbrurk+DOLJTIjUbbQiOxyqohNrPEzY18mdTENAgk1GFPLAuMhBVP4jLAwidxrUiOrCY5+SE1ZFfjKViCWPGQoKYZCXmtP+LeRYat7cM5SfcHZbhAtifxdFgXz+0GMgezetjxURTi1WTotm7IJc3H77ESOofniKbMdZVruQ6tFYImJW9n3/iBLoxJ27QlYoOUoAwZVZCCTc4JL0rE5Pl3lWa9plTRdID+8tz7vH4iZIosOZFo1HxKJQIPPG67KkJPsRivGejTtg5LBdfKMfY25paHpj7QgeaODo0PIBq8ktpEvIj31rVkDJXDsthVceSfIwWWYssx7MYbTFBRzN4Xs0EL+MnT9rX4x1JfgBmLqtk1OqW6sGqsjrzpbUVJY9fi4at4F6LBqwMrFp0VjxEK08XijV2pfQiGlEdj2vN8/knOGqZTYBMPW/Hfso+1hx2OuEVDhwGehCD9LKH/5vfKjRZUT54+pFHeVg4arhfNLiJl9lNjSD6VbjveZg+RJhUw1GEntulbW/yDVE8ZaTyR8jWVsIyaeeiNu99JT96fO/Y1bFL2dmX9n0wKFO95QJa9k17A5LLTTAoKhWpAkTS5CIK65UW |
Install | false |
BDOS | false |
Anti-VM | false |
Install-Folder | %AppData% |
Ports | 6090 |
Mutex | loganwolverin202 |
Delay | 3 |
Group | cookiestempo |
Name0 | Value |
---|---|
Info | PE Detect: PeReader OK (file layout) |
Module Name | AsyncClient.exe |
Full Name | AsyncClient.exe |
EntryPoint | System.Void Client.Program::Main() |
Scope Name | AsyncClient.exe |
Scope Type | ModuleDef |
Kind | Windows |
Runtime Version | v4.0.30319 |
Tables Header Version | 512 |
WinMD Version | <null> |
Assembly Name | AsyncClient |
Assembly Version | 1.0.0.0 |
Assembly Culture | <null> |
Has PublicKey | False |
PublicKey Token | <null> |
Target Framework | .NETFramework,Version=v4.6 |
Total Strings | 431 |
Main Method | System.Void Client.Program::Main() |
Main IL Instruction Count | 64 |
Main IL | ldc.i4.0 <null> stloc.0 <null> br IL_0015: ldloc.0 ldc.i4 1000 call System.Void System.Threading.Thread::Sleep(System.Int32) ldloc.0 <null> ldc.i4.1 <null> add <null> stloc.0 <null> ldloc.0 <null> ldsfld System.String Client.Settings::Delay call System.Int32 System.Convert::ToInt32(System.String) blt.s IL_0007: ldc.i4 1000 call System.Boolean Client.Settings::InitializeSettings() brtrue IL_0032: nop ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Boolean Client.Helper.MutexControl::CreateMutex() brtrue IL_0043: ldsfld System.String Client.Settings::Anti ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) ldsfld System.String Client.Settings::Anti call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_0057: ldsfld System.String Client.Settings::Install call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis() ldsfld System.String Client.Settings::Install call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_006B: ldsfld System.String Client.Settings::BDOS call System.Void Client.Install.NormalStartup::Install() ldsfld System.String Client.Settings::BDOS call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_0089: call System.Void Client.Helper.Methods::PreventSleep() call System.Boolean Client.Helper.Methods::IsAdmin() brfalse IL_0089: call System.Void Client.Helper.Methods::PreventSleep() call System.Void Client.Helper.ProcessCritical::Set() call System.Void Client.Helper.Methods::PreventSleep() ldnull <null> ldftn System.Void Client.Helper.Methods::LastAct() newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr) newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart) callvirt System.Void System.Threading.Thread::Start() ldsfld System.String Client.Settings::offlineKL call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_00C9: leave IL_00D4 ldnull <null> ldftn System.Void Client.Helper.LimeLogger::callk() newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr) newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart) callvirt System.Void System.Threading.Thread::Start() leave IL_00D4: nop pop <null> leave IL_00D4: nop nop <null> call System.Boolean Client.Connection.ClientSocket::get_IsConnected() brtrue IL_00E9: leave IL_00F4 call System.Void Client.Connection.ClientSocket::Reconnect() call System.Void Client.Connection.ClientSocket::InitializeClient() leave IL_00F4: ldc.i4 5000 pop <null> leave IL_00F4: ldc.i4 5000 ldc.i4 5000 call System.Void System.Threading.Thread::Sleep(System.Int32) br.s IL_00D4: nop |
Module Name | AsyncClient.exe |
Full Name | AsyncClient.exe |
EntryPoint | System.Void Client.Program::Main() |
Scope Name | AsyncClient.exe |
Scope Type | ModuleDef |
Kind | Windows |
Runtime Version | v4.0.30319 |
Tables Header Version | 512 |
WinMD Version | <null> |
Assembly Name | AsyncClient |
Assembly Version | 1.0.0.0 |
Assembly Culture | <null> |
Has PublicKey | False |
PublicKey Token | <null> |
Target Framework | .NETFramework,Version=v4.6 |
Total Strings | 431 |
Main Method | System.Void Client.Program::Main() |
Main IL Instruction Count | 64 |
Main IL | ldc.i4.0 <null> stloc.0 <null> br IL_0015: ldloc.0 ldc.i4 1000 call System.Void System.Threading.Thread::Sleep(System.Int32) ldloc.0 <null> ldc.i4.1 <null> add <null> stloc.0 <null> ldloc.0 <null> ldsfld System.String Client.Settings::Delay call System.Int32 System.Convert::ToInt32(System.String) blt.s IL_0007: ldc.i4 1000 call System.Boolean Client.Settings::InitializeSettings() brtrue IL_0032: nop ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Boolean Client.Helper.MutexControl::CreateMutex() brtrue IL_0043: ldsfld System.String Client.Settings::Anti ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) ldsfld System.String Client.Settings::Anti call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_0057: ldsfld System.String Client.Settings::Install call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis() ldsfld System.String Client.Settings::Install call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_006B: ldsfld System.String Client.Settings::BDOS call System.Void Client.Install.NormalStartup::Install() ldsfld System.String Client.Settings::BDOS call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_0089: call System.Void Client.Helper.Methods::PreventSleep() call System.Boolean Client.Helper.Methods::IsAdmin() brfalse IL_0089: call System.Void Client.Helper.Methods::PreventSleep() call System.Void Client.Helper.ProcessCritical::Set() call System.Void Client.Helper.Methods::PreventSleep() ldnull <null> ldftn System.Void Client.Helper.Methods::LastAct() newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr) newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart) callvirt System.Void System.Threading.Thread::Start() ldsfld System.String Client.Settings::offlineKL call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_00C9: leave IL_00D4 ldnull <null> ldftn System.Void Client.Helper.LimeLogger::callk() newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr) newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart) callvirt System.Void System.Threading.Thread::Start() leave IL_00D4: nop pop <null> leave IL_00D4: nop nop <null> call System.Boolean Client.Connection.ClientSocket::get_IsConnected() brtrue IL_00E9: leave IL_00F4 call System.Void Client.Connection.ClientSocket::Reconnect() call System.Void Client.Connection.ClientSocket::InitializeClient() leave IL_00F4: ldc.i4 5000 pop <null> leave IL_00F4: ldc.i4 5000 ldc.i4 5000 call System.Void System.Threading.Thread::Sleep(System.Int32) br.s IL_00D4: nop |
Name0 | Value |
---|---|
Key (AES_256) | bGlMMVRvamlOcFFEOGN2Mkpsc2VxSWZCMUdDbHNJR3Y= |
Ports | 6090 |
Mutex | loganwolverin202 |
Config. Field0 | Value |
---|---|
Key (AES_256) | bGlMMVRvamlOcFFEOGN2Mkpsc2VxSWZCMUdDbHNJR3Y= |
Pastebin | - |
Certificate | MIIE8jCCAtqgAwIBAgIQAOQb7nA/hP/L1XXxqdDJNzANBgkqhkiG9w0BAQ0FADAaMRgwFgYDVQQDDA9Bc3luY1JBVCBTZXJ2ZXIwIBcNMjMwNTI1MDUyMTIyWhgPOTk5OTEyMzEyMzU5NTlaMBoxGDAWBgNVBAMMD0FzeW5jUkFUIFNlcnZlcjCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAIykAVxs0s6rZ/dwP6ujJtpnj6RSsCsZN6Cfj1InZxSIswX+zNiKJys8xyLlyexoya3ebLp5gOSzNvGMlxluLm9vCaayOzt8HuaCCUFntv/AIiigkbE2gqVYjh7qdObXhyhAgjuygHDP0QCc+VzP1aVH4CesUy1gGvxgOgmdXok2AjCssH69OYGA/DAdEzaOK7TtFqS2qqCzCldLuNBa2xy0/Yb73Zko42hlx+hvp/ciTNyFDXqIBdUIu/6X3on+ecdW8SiLMjzr8Xf1BHcoVgTbDto7EpNq2a1b2CjI23YMlc+mRq33k6R2Dw0NNZmNdnTjnFFVmZZ419g2qIxR+JetlOui7Lc77pKX5Om0+HBZqQYKTCxMVykxz0G7EuAxIXG01Wlogv1Ulj31UH2APYQpgRyZ2DUhqJ1Ls3MLxd3X4UJ00DLnhOQf4bSxqZityJ+17tFLj/qSw8niWYm9lzor2652DmCyw2tFMOnkrnBStNaymtyE5JiN3hZ+3xLlCShjHbR6ANpnmPJJWyUnVLHzYj9Fg5cVrfcIHfGDxkh6P/x32CuG1uzxFS0NsZIG6dsiNmBJLZ/B+JQp2V5a1ux3bwzlgEd3OYdDAf8KzXjFmnhfLqhBN/e33eAYdLtZ5ijj9VTACHiEA73NNTROv+9MrHe+jlDqDX+JFS2HTRktAgMBAAGjMjAwMB0GA1UdDgQWBBSGuCNUrBGiR5cyCuX6uVeVEgA8yDAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBDQUAA4ICAQBBMeYWK/JJKSBUsQ4Ba2RHStyT+uunyfCP9ht58sDUygZWxFQxl4Tmw1JLTRjU2FNia9d73P3k7BuDux/zSWJy0rc+Yr5H174M86L7rXyM/dhyZ26Ansn3rxNG7OJP+UQh559z7wwa5sVstFlVyAZOYFBUGGGMhCK/odXhRgJxnWwPR5LKzbQKGXNsvYfnyjWsh65631ZSMvoH3eblBluOwhvCHP7MotRPD8xkmMfIL9npMprJRPHco5MnenLv9c1R6x7AS93fEh359l3fOdL1LTU5K7Q0FydPztV19HDkJyotROS1hOiWze1LNQLXQ6701jb20bIcxeeWyfzJSew1p6j/iIvbBBEKoeQVx6gCXN2UHfZRzeoQKzWQPJ9EDaobDIZ6VyBJ3Vg2zCuFtLL73oJzycow0Rudn/2O9FHy6rucrLcyWxi4AiH+a0b2l1GwvZ/46TUdGFvygMflzdSxf/sVeCrYOTxXJBAnCyz1Yx5hcFI/lblBL70necTt0FDnwHQSWyrdouWYWlGupZ9HUKg6IpGEg9tx0mwyvIycHXTeeQ+NVHYR+WmbVcgYy5HIMPPOyAV7FVCjvRfQ9GofgzRasjDKSqMeWChkMC2zMjI6j6WzWDK5ZD6mCcTiP5P0f3tOkYV/+cw2elMNBmmDAnZVPwweENRxZ/YelFug7Q== |
ServerSignature | RzLYst500hncDWwVOCXGSYphAQJEGhQIteg8UXWmArkDswJnvvdK43oU+/eIi4uNkQb1Pbrurk+DOLJTIjUbbQiOxyqohNrPEzY18mdTENAgk1GFPLAuMhBVP4jLAwidxrUiOrCY5+SE1ZFfjKViCWPGQoKYZCXmtP+LeRYat7cM5SfcHZbhAtifxdFgXz+0GMgezetjxURTi1WTotm7IJc3H77ESOofniKbMdZVruQ6tFYImJW9n3/iBLoxJ27QlYoOUoAwZVZCCTc4JL0rE5Pl3lWa9plTRdID+8tz7vH4iZIosOZFo1HxKJQIPPG67KkJPsRivGejTtg5LBdfKMfY25paHpj7QgeaODo0PIBq8ktpEvIj31rVkDJXDsthVceSfIwWWYssx7MYbTFBRzN4Xs0EL+MnT9rX4x1JfgBmLqtk1OqW6sGqsjrzpbUVJY9fi4at4F6LBqwMrFp0VjxEK08XijV2pfQiGlEdj2vN8/knOGqZTYBMPW/Hfso+1hx2OuEVDhwGehCD9LKH/5vfKjRZUT54+pFHeVg4arhfNLiJl9lNjSD6VbjveZg+RJhUw1GEntulbW/yDVE8ZaTyR8jWVsIyaeeiNu99JT96fO/Y1bFL2dmX9n0wKFO95QJa9k17A5LLTTAoKhWpAkTS5CIK65UW |
Install | false |
BDOS | false |
Anti-VM | false |
Install-Folder | %AppData% |
Ports | 6090 |
Mutex | loganwolverin202 |
Delay | 3 |
Group | cookiestempo |
Name0 | Value | Location |
---|---|---|
Key (AES_256) | bGlMMVRvamlOcFFEOGN2Mkpsc2VxSWZCMUdDbHNJR3Y= Malicious |
885127590b2c7ec029e1c5aab5d0635a |
Ports | 6090 Malicious |
885127590b2c7ec029e1c5aab5d0635a |
Mutex | loganwolverin202 Malicious |
885127590b2c7ec029e1c5aab5d0635a |