a3b170e1a9e66a6a3bc0ddb4c145cba5
PE Executable | MD5: a3b170e1a9e66a6a3bc0ddb4c145cba5 | Size: 2.72 MB | application/x-dosexec
Symbol Obfuscation Score
|
Hash | Hash Value |
|---|---|
| MD5 | a3b170e1a9e66a6a3bc0ddb4c145cba5
|
| Sha1 | 7358de0962f406fa775475bf42c3695fe5800f9b
|
| Sha256 | f5f0e52163104f81b6897b23284e625d9ddcab36751c1552b64a73004f824cf2
|
| Sha384 | 0e4ca7ace418c2cb385ce79d6411294e1755b05c66c6df97b83a772bad844b3d2a0b4c21f7f9b9264de2a5ee5e79b2f7
|
| Sha512 | 1473e8aa4133b2f0427aec7911591b6e16467286e3d7563e5dcbc5b8c007de207ca0b4613014832e4da8324b9512fd89cb56b0fb8d7e748b4c5a3f8127315919
|
| SSDeep | 49152:fPu6NL4xi8/N+ZZXZQOLHM7wRPirm2NnPTKKm77LrwCB6uanU:nu6tSi8VIxpL7oZNn2Km77LrwkFWU
|
| TLSH | 4DC5F01077F9810AF3BF5BB9ABB6144D0B77B903EA7AD39E244840990FA33509E51763
|
PeID
|
Config. Field0 | Value |
|---|---|
| Conf. AES-Salt | BF-EB-1E-56-FB-CD-97-3B-B2-19-02-24-30-A5-78-43-00-3D-56-44-D2-1E-62-B9-D4-F1-80-E7-E6-C3-39-41 |
| Conf. AES-Key | |
| Version | ObjectLength |
| Port | ChainingModeGCM |
| Host | ChainingModeGCM |
| ReconnectDelay | AuthTagLength |
| Key | ChainingMode |
| SubDirectory | KeyDataBlob |
| InstallName | AES |
| Install | Microsoft Primitive Provider |
| Startup | 1 |
| Mutex | 1 |
| StartupKey | -1073700862 |
| HideFile | ObjectLength |
| EnableLogger | ChainingModeGCM |
| EncryptionKey | AuthTagLength |
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: ? |
| Module Name | Client.exe |
| Full Name | Client.exe |
| EntryPoint | System.Void eaujebyrcsptysfiwmm.YhniEbRjIERWwMY3TJ::Main() |
| Scope Name | Client.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Client |
| Assembly Version | 1.6.6.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 2147 |
| Main Method | System.Void eaujebyrcsptysfiwmm.YhniEbRjIERWwMY3TJ::Main() |
| Main IL Instruction Count | 11 |
| Main IL | ldc.i4 3072 call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType) ldc.i4.2 <null> call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode) call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) call System.Void eaujebyrcsptysfiwmm.YhniEbRjIERWwMY3TJ::umZYDStoud3hoeCkS6lvaBYI() newobj System.Void eaujebyrcsptysfiwmm.pITtYg7WxOGBpJqoS4wHcrUR::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null> |
| Module Name | Client.exe |
| Full Name | Client.exe |
| EntryPoint | System.Void eaujebyrcsptysfiwmm.YhniEbRjIERWwMY3TJ::Main() |
| Scope Name | Client.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Client |
| Assembly Version | 1.6.6.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 2147 |
| Main Method | System.Void eaujebyrcsptysfiwmm.YhniEbRjIERWwMY3TJ::Main() |
| Main IL Instruction Count | 11 |
| Main IL | ldc.i4 3072 call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType) ldc.i4.2 <null> call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode) call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) call System.Void eaujebyrcsptysfiwmm.YhniEbRjIERWwMY3TJ::umZYDStoud3hoeCkS6lvaBYI() newobj System.Void eaujebyrcsptysfiwmm.pITtYg7WxOGBpJqoS4wHcrUR::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null> |
|
Name0 | Value |
|---|---|
| CnC | ChainingModeGCM |
| Port | ChainingModeGCM |
|
Config. Field0 | Value |
|---|---|
| Conf. AES-Salt | BF-EB-1E-56-FB-CD-97-3B-B2-19-02-24-30-A5-78-43-00-3D-56-44-D2-1E-62-B9-D4-F1-80-E7-E6-C3-39-41 |
| Conf. AES-Key | |
| Version | ObjectLength |
| Port | ChainingModeGCM |
| Host | ChainingModeGCM |
| ReconnectDelay | AuthTagLength |
| Key | ChainingMode |
| SubDirectory | KeyDataBlob |
| InstallName | AES |
| Install | Microsoft Primitive Provider |
| Startup | 1 |
| Mutex | 1 |
| StartupKey | -1073700862 |
| HideFile | ObjectLength |
| EnableLogger | ChainingModeGCM |
| EncryptionKey | AuthTagLength |
|
Name0 | Value | Location |
|---|---|---|
| CnC | ChainingModeGCM Malicious |
a3b170e1a9e66a6a3bc0ddb4c145cba5 |
| Port | ChainingModeGCM Malicious |
a3b170e1a9e66a6a3bc0ddb4c145cba5 |