a64c435405ce85d59fec18b82900ec0e
PE Executable | MD5: a64c435405ce85d59fec18b82900ec0e | Size: 1.95 MB | application/x-dosexec
Symbol Ofbuscation Score
|
Hash | Hash Value |
|---|---|
| MD5 | a64c435405ce85d59fec18b82900ec0e
|
| Sha1 | 1435a7c8df54f855ad43d6074c77bb4033459de8
|
| Sha256 | 2c9a9dad74ed9892e2d73dc8a1bbfcdd46d6d9d54a4625a803842d734a5a8ec2
|
| Sha384 | 594eb3a7393da8901ef5fca1e463369bec84989131d53f859b3929db5702b48dd938bfb7ee46f1d3b677d8db768fc88b
|
| Sha512 | 3253804efee05fcc757c88b655336b823ad57498808b3cc1b0ded48bbd421cf384da1c2c9355e6cfb82370478cb9767b66fdd02ef3f438c0d494f14c49d71cf6
|
| SSDeep | 49152:B2WEf7rRFirm+Nn42KK8i7Ltwa+VVaSzm:B2WEHavNnoK8i7LtwbHJz
|
| TLSH | F9950110B3F58146F1FF5BB8A4B758450B77BA03AA36C75F5988A09D1EA3740CE913A3
|
PeID
|
Name0 | Value |
|---|---|
| Module Name | Client.exe |
| Full Name | Client.exe |
| EntryPoint | System.Void grkceucjzj.lsTXHR2IinuNBgOTS0huffh::Main() |
| Scope Name | Client.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Client |
| Assembly Version | 1.6.6.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 1528 |
| Main Method | System.Void grkceucjzj.lsTXHR2IinuNBgOTS0huffh::Main() |
| Main IL Instruction Count | 11 |
| Main IL | ldc.i4 3072 call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType) ldc.i4.2 <null> call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode) call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) call System.Void grkceucjzj.lsTXHR2IinuNBgOTS0huffh::KKKhBTtReVVv() newobj System.Void grkceucjzj.01wjqdJqMdV::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null> |
| Module Name | Client.exe |
| Full Name | Client.exe |
| EntryPoint | System.Void grkceucjzj.lsTXHR2IinuNBgOTS0huffh::Main() |
| Scope Name | Client.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Client |
| Assembly Version | 1.6.6.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 1528 |
| Main Method | System.Void grkceucjzj.lsTXHR2IinuNBgOTS0huffh::Main() |
| Main IL Instruction Count | 11 |
| Main IL | ldc.i4 3072 call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType) ldc.i4.2 <null> call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode) call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) call System.Void grkceucjzj.lsTXHR2IinuNBgOTS0huffh::KKKhBTtReVVv() newobj System.Void grkceucjzj.01wjqdJqMdV::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null> |
|
Name0 | Value |
|---|---|
| Embedded Resources | 31 |
| Suspicious Type Names (1-2 chars) | 0 |
| Embedded Resources | 0 |
| Suspicious Type Names (1-2 chars) | 0 |
| Embedded Resources | 0 |
| Suspicious Type Names (1-2 chars) | 0 |
| Embedded Resources | 2 |
| Suspicious Type Names (1-2 chars) | 0 |
| Embedded Resources | 0 |
| Suspicious Type Names (1-2 chars) | 0 |
| Embedded Resources | 0 |
| Suspicious Type Names (1-2 chars) | 0 |
| Embedded Resources | 0 |
| Suspicious Type Names (1-2 chars) | 0 |
| Embedded Resources | 6 |
| Suspicious Type Names (1-2 chars) | 0 |
| Embedded Resources | 0 |
| Suspicious Type Names (1-2 chars) | 0 |
| Embedded Resources | 0 |
| Suspicious Type Names (1-2 chars) | 0 |
| Embedded Resources | 0 |
| Suspicious Type Names (1-2 chars) | 0 |
| Embedded Resources | 0 |
| Suspicious Type Names (1-2 chars) | 0 |
| Embedded Resources | 0 |
| Suspicious Type Names (1-2 chars) | 0 |
| Embedded Resources | 0 |
| Suspicious Type Names (1-2 chars) | 0 |
| Embedded Resources | 0 |
| Suspicious Type Names (1-2 chars) | 0 |
| Embedded Resources | 0 |
| Suspicious Type Names (1-2 chars) | 0 |
| Embedded Resources | 0 |
| Suspicious Type Names (1-2 chars) | 0 |
| Embedded Resources | 1 |
| Suspicious Type Names (1-2 chars) | 2 |
| Embedded Resources | 2 |
| Suspicious Type Names (1-2 chars) | 2 |
| Embedded Resources | 1 |
| Suspicious Type Names (1-2 chars) | 2 |
| Embedded Resources | 1 |
| Suspicious Type Names (1-2 chars) | 2 |
| Embedded Resources | 0 |
| Suspicious Type Names (1-2 chars) | 0 |
| Embedded Resources | 0 |
| Suspicious Type Names (1-2 chars) | 0 |
|
Name0 | Value | Location |
|---|---|---|
| Embedded Resources | 31 |
a64c435405ce85d59fec18b82900ec0e |
| Suspicious Type Names (1-2 chars) | 0 |
a64c435405ce85d59fec18b82900ec0e |
| Embedded Resources | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.aforge.dll |
| Suspicious Type Names (1-2 chars) | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.aforge.dll |
| Embedded Resources | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.aforge.video.dll |
| Suspicious Type Names (1-2 chars) | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.aforge.video.dll |
| Embedded Resources | 2 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.aforge.video.directshow.dll |
| Suspicious Type Names (1-2 chars) | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.aforge.video.directshow.dll |
| Embedded Resources | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.gma.system.mousekeyhook.dll |
| Suspicious Type Names (1-2 chars) | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.gma.system.mousekeyhook.dll |
| Embedded Resources | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.naudio.core.dll |
| Suspicious Type Names (1-2 chars) | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.naudio.core.dll |
| Embedded Resources | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.naudio.wasapi.dll |
| Suspicious Type Names (1-2 chars) | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.naudio.wasapi.dll |
| Embedded Resources | 6 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.naudio.winforms.dll |
| Suspicious Type Names (1-2 chars) | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.naudio.winforms.dll |
| Embedded Resources | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.naudio.winmm.dll |
| Suspicious Type Names (1-2 chars) | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.naudio.winmm.dll |
| Embedded Resources | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.protobuf-net.dll |
| Suspicious Type Names (1-2 chars) | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.protobuf-net.dll |
| Embedded Resources | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.protobuf-net.core.dll |
| Suspicious Type Names (1-2 chars) | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.protobuf-net.core.dll |
| Embedded Resources | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.sharpdx.dll |
| Suspicious Type Names (1-2 chars) | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.sharpdx.dll |
| Embedded Resources | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.sharpdx.d3dcompiler.dll |
| Suspicious Type Names (1-2 chars) | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.sharpdx.d3dcompiler.dll |
| Embedded Resources | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.sharpdx.direct2d1.dll |
| Suspicious Type Names (1-2 chars) | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.sharpdx.direct2d1.dll |
| Embedded Resources | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.sharpdx.direct3d11.dll |
| Suspicious Type Names (1-2 chars) | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.sharpdx.direct3d11.dll |
| Embedded Resources | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.sharpdx.dxgi.dll |
| Suspicious Type Names (1-2 chars) | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.sharpdx.dxgi.dll |
| Embedded Resources | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.sharpdx.mathematics.dll |
| Suspicious Type Names (1-2 chars) | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.sharpdx.mathematics.dll |
| Embedded Resources | 1 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.system.buffers.dll |
| Suspicious Type Names (1-2 chars) | 2 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.system.buffers.dll |
| Embedded Resources | 2 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.system.collections.immutable.dll |
| Suspicious Type Names (1-2 chars) | 2 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.system.collections.immutable.dll |
| Embedded Resources | 1 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.system.memory.dll |
| Suspicious Type Names (1-2 chars) | 2 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.system.memory.dll |
| Embedded Resources | 1 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.system.numerics.vectors.dll |
| Suspicious Type Names (1-2 chars) | 2 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.system.numerics.vectors.dll |
| Embedded Resources | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.system.runtime.compilerservices.unsafe.dll |
| Suspicious Type Names (1-2 chars) | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.system.runtime.compilerservices.unsafe.dll |
| Embedded Resources | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.pulsar.common.dll |
| Suspicious Type Names (1-2 chars) | 0 |
a64c435405ce85d59fec18b82900ec0e > .Net Resources > costura.pulsar.common.dll |