Suspicious
Suspect

8b2cb4d2384f41efedd6035efd4ecbb4

PE Executable
|
MD5: 8b2cb4d2384f41efedd6035efd4ecbb4
|
Size: 666.11 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
8b2cb4d2384f41efedd6035efd4ecbb4
Sha1
7bc7433aab61f05f005756291e17d2d9def31e0b
Sha256
31cd0a970953310b8cd8a5418eafb8a992e530cdb62ff19ddd72e15338e7ef71
Sha384
8f9eb7b9b1812c79a398a658755bfe8a55743dd31d473bc6b759401818c3a314d1a1a095fb8a6044f4062625dcb4683d
Sha512
8c7ed1217e7d9e672395a6f44ca65588626d7b8b6119dd8f846b68066ccd41f9bd0a87234e9e322690f37543a938cc00d98f0c0472d04487aa246f4c867657a8
SSDeep
6144:0JBVJc9zxaAhR+h0phLLWzeZmccJInzMJdHmF3r209Dx1NbsECsD35EhDmQctnzh:0JPJghhw6pJftLm83/KECsb5xzD5p5
TLSH
A6E4A20CBD51FC14CE6E3DB38BE690A11B3210C63F22A116335A6EF95B593B649A317D

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
clhkvnuzyfbn
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Client.exe

Full Name

Client.exe

EntryPoint

System.Void ھڊڇۆۆۇیۉګڊګڤڎڝی.ۊہڈډۂۆڜڎڲۂ::ڤڊۂۉڋڜڋڿډڍڒ(System.String[])

Scope Name

Client.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Client

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

1681

Main Method

System.Void ھڊڇۆۆۇیۉګڊګڤڎڝی.ۊہڈډۂۆڜڎڲۂ::ڤڊۂۉڋڜڋڿډڍڒ(System.String[])

Main IL Instruction Count

141

Main IL

ldc.i4 3415 stloc.1 <null> br IL_01E8: br IL_000B nop <null> ldloc.1 <null> ldc.i4 3445 ceq <null> brfalse IL_0029: nop call System.Boolean ھڊڇۆۆۇیۉګڊګڤڎڝی.ڽڎڞڑڈڲہۆۂہ::ڬڍگڐڱڰڬۆڎډڮہڊڞ() brfalse IL_0055: ret ldc.i4 3453 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3453 ceq <null> brfalse IL_0047: nop call System.Boolean ھڊڇۆۆۇیۉګڊګڤڎڝی.ۈڬۍڇھڱۊګڎڬڰڲ::ڜڿڰہۈڬۇڮڱۇۂۍڰڑ() brtrue IL_006A: newobj System.Void System.Random::.ctor() ldc.i4 3458 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3458 ceq <null> brfalse IL_005C: nop ret <null> ldc.i4 3460 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3460 ceq <null> brfalse IL_00B6: nop newobj System.Void System.Random::.ctor() nop <null> ldc.r8 2 ldc.r8 50 mul <null> call System.Int32 System.Convert::ToInt32(System.Double) nop <null> ldc.r8 1500 ldc.r8 500 call System.Double System.Math::Floor(System.Double) sub <null> call System.Int32 System.Convert::ToInt32(System.Double) callvirt System.Int32 System.Random::Next(System.Int32,System.Int32) call System.Void System.Threading.Thread::Sleep(System.Int32) ldc.i4 3468 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3439 ceq <null> brfalse IL_00CF: nop call System.Void ھڊڇۆۆۇیۉګڊګڤڎڝی.گۇہڜڮۀۂڤۋڲڞڮھڇ::ڜڋڝۈڽڈڌڭڈۈڊڋۀیۋ() ldc.i4 3445 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3433 ceq <null> brfalse IL_00E8: nop call System.Void ھڊڇۆۆۇیۉګڊګڤڎڝی.ډۊڱھڱڋڱڜڞڜڤڈڤڋۆ::ڬڍڞڲۈڮڽڤۍڍڤۀ() ldc.i4 3439 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3482 ceq <null> brfalse IL_010A: nop ldloc V_0 ldfld System.Boolean ھڊڇۆۆۇیۉګڊګڤڎڝی.ۀڤڱڎڽڬڇڽیۇ::ڮڤڑڱڲڤڋۆڍڋڲډڊڜڜ brtrue IL_0135: newobj System.Void System.Random::.ctor() ldc.i4 3489 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3489 ceq <null> brfalse IL_0127: nop ldloc V_0 callvirt System.Void ھڊڇۆۆۇیۉګڊګڤڎڝی.ۀڤڱڎڽڬڇڽیۇ::ڱڌڈګۈڮۈۍ() ldc.i4 3492 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3492 ceq <null> brfalse IL_0186: nop newobj System.Void System.Random::.ctor() nop <null> ldc.r8 103.91202300542814 ldc.r8 50 call System.Double System.Math::Log(System.Double) sub <null> call System.Int32 System.Convert::ToInt32(System.Double) nop <null> ldc.r8 500 ldc.r8 500 call System.Double System.Math::Ceiling(System.Double) add <null> call System.Int32 System.Convert::ToInt32(System.Double) callvirt System.Int32 System.Random::Next(System.Int32,System.Int32) call System.Void System.Threading.Thread::Sleep(System.Int32) ldc.i4 3499 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3468 ceq <null> brfalse IL_01A3: nop newobj System.Void ھڊڇۆۆۇیۉګڊګڤڎڝی.ۀڤڱڎڽڬڇڽیۇ::.ctor() stloc V_0 ldc.i4 3476 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3476 ceq <null> brfalse IL_01C0: nop ldloc V_0 callvirt System.Void ھڊڇۆۆۇیۉګڊګڤڎڝی.ۀڤڱڎڽڬڇڽیۇ::ڱڌڈګۈڮۈۍ() ldc.i4 3482 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3415 ceq <null> brfalse IL_01D5: nop nop <null> ldc.i4 3433 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3499 ceq <null> brfalse IL_01E8: br IL_000B br IL_01ED: br IL_00F6 br IL_000B: nop br IL_00F6: ldloc V_0

Module Name

Client.exe

Full Name

Client.exe

EntryPoint

System.Void ھڊڇۆۆۇیۉګڊګڤڎڝی.ۊہڈډۂۆڜڎڲۂ::ڤڊۂۉڋڜڋڿډڍڒ(System.String[])

Scope Name

Client.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Client

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

1681

Main Method

System.Void ھڊڇۆۆۇیۉګڊګڤڎڝی.ۊہڈډۂۆڜڎڲۂ::ڤڊۂۉڋڜڋڿډڍڒ(System.String[])

Main IL Instruction Count

141

Main IL

ldc.i4 3415 stloc.1 <null> br IL_01E8: br IL_000B nop <null> ldloc.1 <null> ldc.i4 3445 ceq <null> brfalse IL_0029: nop call System.Boolean ھڊڇۆۆۇیۉګڊګڤڎڝی.ڽڎڞڑڈڲہۆۂہ::ڬڍگڐڱڰڬۆڎډڮہڊڞ() brfalse IL_0055: ret ldc.i4 3453 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3453 ceq <null> brfalse IL_0047: nop call System.Boolean ھڊڇۆۆۇیۉګڊګڤڎڝی.ۈڬۍڇھڱۊګڎڬڰڲ::ڜڿڰہۈڬۇڮڱۇۂۍڰڑ() brtrue IL_006A: newobj System.Void System.Random::.ctor() ldc.i4 3458 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3458 ceq <null> brfalse IL_005C: nop ret <null> ldc.i4 3460 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3460 ceq <null> brfalse IL_00B6: nop newobj System.Void System.Random::.ctor() nop <null> ldc.r8 2 ldc.r8 50 mul <null> call System.Int32 System.Convert::ToInt32(System.Double) nop <null> ldc.r8 1500 ldc.r8 500 call System.Double System.Math::Floor(System.Double) sub <null> call System.Int32 System.Convert::ToInt32(System.Double) callvirt System.Int32 System.Random::Next(System.Int32,System.Int32) call System.Void System.Threading.Thread::Sleep(System.Int32) ldc.i4 3468 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3439 ceq <null> brfalse IL_00CF: nop call System.Void ھڊڇۆۆۇیۉګڊګڤڎڝی.گۇہڜڮۀۂڤۋڲڞڮھڇ::ڜڋڝۈڽڈڌڭڈۈڊڋۀیۋ() ldc.i4 3445 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3433 ceq <null> brfalse IL_00E8: nop call System.Void ھڊڇۆۆۇیۉګڊګڤڎڝی.ډۊڱھڱڋڱڜڞڜڤڈڤڋۆ::ڬڍڞڲۈڮڽڤۍڍڤۀ() ldc.i4 3439 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3482 ceq <null> brfalse IL_010A: nop ldloc V_0 ldfld System.Boolean ھڊڇۆۆۇیۉګڊګڤڎڝی.ۀڤڱڎڽڬڇڽیۇ::ڮڤڑڱڲڤڋۆڍڋڲډڊڜڜ brtrue IL_0135: newobj System.Void System.Random::.ctor() ldc.i4 3489 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3489 ceq <null> brfalse IL_0127: nop ldloc V_0 callvirt System.Void ھڊڇۆۆۇیۉګڊګڤڎڝی.ۀڤڱڎڽڬڇڽیۇ::ڱڌڈګۈڮۈۍ() ldc.i4 3492 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3492 ceq <null> brfalse IL_0186: nop newobj System.Void System.Random::.ctor() nop <null> ldc.r8 103.91202300542814 ldc.r8 50 call System.Double System.Math::Log(System.Double) sub <null> call System.Int32 System.Convert::ToInt32(System.Double) nop <null> ldc.r8 500 ldc.r8 500 call System.Double System.Math::Ceiling(System.Double) add <null> call System.Int32 System.Convert::ToInt32(System.Double) callvirt System.Int32 System.Random::Next(System.Int32,System.Int32) call System.Void System.Threading.Thread::Sleep(System.Int32) ldc.i4 3499 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3468 ceq <null> brfalse IL_01A3: nop newobj System.Void ھڊڇۆۆۇیۉګڊګڤڎڝی.ۀڤڱڎڽڬڇڽیۇ::.ctor() stloc V_0 ldc.i4 3476 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3476 ceq <null> brfalse IL_01C0: nop ldloc V_0 callvirt System.Void ھڊڇۆۆۇیۉګڊګڤڎڝی.ۀڤڱڎڽڬڇڽیۇ::ڱڌڈګۈڮۈۍ() ldc.i4 3482 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3415 ceq <null> brfalse IL_01D5: nop nop <null> ldc.i4 3433 stloc.1 <null> nop <null> ldloc.1 <null> ldc.i4 3499 ceq <null> brfalse IL_01E8: br IL_000B br IL_01ED: br IL_00F6 br IL_000B: nop br IL_00F6: ldloc V_0

8b2cb4d2384f41efedd6035efd4ecbb4 (666.11 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙