Symbol Obfuscation Score
|
Hash | Hash Value |
|---|---|
| MD5 | a7ee0066dd2cf11a38226709c76c314d
|
| Sha1 | 8370e6f71a2dea8dbdf739a549f740c98153246f
|
| Sha256 | feec3cf0f4281220ada2bb20bd59a3254e7543d65631a4a0deae019ffc15d277
|
| Sha384 | ccc763ccfb6ee1bc58cad8d6503218383a50b43ea8e5901ef211fcfe1b7e9a9cacab592a876d0c89f300946826e85a00
|
| Sha512 | 99c34a5b29e90383e7b3af00cae219d7858d2a85b8b55f490facc38eda3931a0298c2a377c3696dee2cf5a76f974e68f4261f9336f03860f67ecffaa4f35a2f4
|
| SSDeep | 49152:DcSNWnn7wRPirm2NnPTKKm77LrwCB6uanKy:DR0MoZNn2Km77LrwkFW
|
| TLSH | 7395F050B7F6811AF2FF6BB9A8B718490B37B903EA36D74E0888605D1EB77409D51363
|
PeID
|
Config. Field0 | Value |
|---|---|
| Conf. AES-Salt | BF-EB-1E-56-FB-CD-97-3B-B2-19-02-24-30-A5-78-43-00-3D-56-44-D2-1E-62-B9-D4-F1-80-E7-E6-C3-39-41 |
| Conf. AES-Key | |
| Version | ObjectLength |
| Port | ChainingModeGCM |
| Host | ChainingModeGCM |
| ReconnectDelay | AuthTagLength |
| Key | ChainingMode |
| SubDirectory | KeyDataBlob |
| InstallName | AES |
| Install | Microsoft Primitive Provider |
| Startup | 1 |
| Mutex | 1 |
| StartupKey | -1073700862 |
| HideFile | 0 |
| EnableLogger | 0 |
| EncryptionKey | 0 |
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: ? |
| Module Name | Client.exe |
| Full Name | Client.exe |
| EntryPoint | System.Void knmcswnvpcyvlx.PgkLgUskaheb7QOSRn::Main() |
| Scope Name | Client.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Client |
| Assembly Version | 1.6.5.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 2163 |
| Main Method | System.Void knmcswnvpcyvlx.PgkLgUskaheb7QOSRn::Main() |
| Main IL Instruction Count | 11 |
| Main IL | ldc.i4 3072 call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType) ldc.i4.2 <null> call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode) call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) call System.Void knmcswnvpcyvlx.PgkLgUskaheb7QOSRn::P4IR11k3clAOGvo51PAc() newobj System.Void knmcswnvpcyvlx.MmxmNfU4DhHL8Y8a::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null> |
| Module Name | Client.exe |
| Full Name | Client.exe |
| EntryPoint | System.Void knmcswnvpcyvlx.PgkLgUskaheb7QOSRn::Main() |
| Scope Name | Client.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Client |
| Assembly Version | 1.6.5.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 2163 |
| Main Method | System.Void knmcswnvpcyvlx.PgkLgUskaheb7QOSRn::Main() |
| Main IL Instruction Count | 11 |
| Main IL | ldc.i4 3072 call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType) ldc.i4.2 <null> call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode) call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) call System.Void knmcswnvpcyvlx.PgkLgUskaheb7QOSRn::P4IR11k3clAOGvo51PAc() newobj System.Void knmcswnvpcyvlx.MmxmNfU4DhHL8Y8a::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null> |
|
Name0 | Value |
|---|---|
| CnC | ChainingModeGCM |
| Port | ChainingModeGCM |
|
Config. Field0 | Value |
|---|---|
| Conf. AES-Salt | BF-EB-1E-56-FB-CD-97-3B-B2-19-02-24-30-A5-78-43-00-3D-56-44-D2-1E-62-B9-D4-F1-80-E7-E6-C3-39-41 |
| Conf. AES-Key | |
| Version | ObjectLength |
| Port | ChainingModeGCM |
| Host | ChainingModeGCM |
| ReconnectDelay | AuthTagLength |
| Key | ChainingMode |
| SubDirectory | KeyDataBlob |
| InstallName | AES |
| Install | Microsoft Primitive Provider |
| Startup | 1 |
| Mutex | 1 |
| StartupKey | -1073700862 |
| HideFile | 0 |
| EnableLogger | 0 |
| EncryptionKey | 0 |
|
Name0 | Value | Location |
|---|---|---|
| CnC | ChainingModeGCM Malicious |
a7ee0066dd2cf11a38226709c76c314d |
| Port | ChainingModeGCM Malicious |
a7ee0066dd2cf11a38226709c76c314d |