| Module Name |
|
| Full Name |
|
| EntryPoint |
System.Int32 Stub.Program::Main(System.String[]) |
| Scope Name |
|
| Scope Type |
|
| Kind |
|
| Runtime Version |
|
| Tables Header Version |
|
| WinMD Version |
|
| Assembly Name |
|
| Assembly Version |
|
| Assembly Culture |
|
| Has PublicKey |
|
| PublicKey Token |
|
| Target Framework |
.NETFramework,Version=v4.8 |
| Total Strings |
|
| Main Method |
System.Int32 Stub.Program::Main(System.String[]) |
| Main IL Instruction Count |
|
| Main IL |
ldstr SYSRUNTIME_CTX
call System.String System.Environment::GetEnvironmentVariable(System.String)
dup <null>
brtrue.s IL_0013: stloc.0
pop <null>
ldstr
stloc.0 <null>
ldloc.0 <null>
ldstr d3c0y
call System.Boolean System.String::op_Equality(System.String,System.String)
brfalse.s IL_0029: ldloc.0
ldc.i4.m1 <null>
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldc.i4.0 <null>
ret <null>
ldloc.0 <null>
ldstr r3a1
call System.Boolean System.String::op_Inequality(System.String,System.String)
brfalse.s IL_0065: call System.Void Stub.Program::AntiSandboxDelay()
ldc.i4.0 <null>
stloc.3 <null>
call System.ValueTuple`2<Stub.StubConfig,System.Byte[]> Stub.Program::ReadFromOverlay()
ldfld Stub.StubConfig System.ValueTuple`2<Stub.StubConfig,System.Byte[]>::Item1
callvirt System.Boolean Stub.StubConfig::get_EnableStealthCopy()
stloc.3 <null>
leave.s IL_004D: ldloc.3
pop <null>
leave.s IL_004D: ldloc.3
ldloc.3 <null>
brfalse.s IL_0056: ldstr "SYSRUNTIME_CTX"
call System.Int32 Stub.Program::RelaunchWithRandomName()
ret <null>
ldstr SYSRUNTIME_CTX
ldstr r3a1
call System.Void System.Environment::SetEnvironmentVariable(System.String,System.String)
call System.Void Stub.Program::AntiSandboxDelay()
call System.ValueTuple`2<Stub.StubConfig,System.Byte[]> Stub.Program::ReadFromOverlay()
dup <null>
ldfld Stub.StubConfig System.ValueTuple`2<Stub.StubConfig,System.Byte[]>::Item1
stloc.1 <null>
ldfld System.Byte[] System.ValueTuple`2<Stub.StubConfig,System.Byte[]>::Item2
stloc.2 <null>
leave.s IL_0099: ldloc.1
stloc.s V_4
ldstr Load Error
ldloc.s V_4
callvirt System.String System.Exception::get_Message()
call System.Void Stub.Program::ShowError(System.String,System.String)
ldc.i4.1 <null>
stloc.s V_5
leave IL_011A: ldloc.s V_5
ldloc.1 <null>
callvirt System.Boolean Stub.StubConfig::get_EnableGuard()
brfalse.s IL_00AC: ldloc.1
ldloc.1 <null>
call System.Void Stub.Guard::set_Config(Stub.StubConfig)
call System.Void Stub.Guard::StartMonitoring()
ldloc.1 <null>
callvirt System.Boolean Stub.StubConfig::get_EnableDecoy()
brfalse.s IL_00B9: nop
call System.Void Stub.Decoy::Spawn()
nop <null>
ldloc.2 <null>
ldloc.1 <null>
callvirt System.Byte[] Stub.StubConfig::get_KeyBytes()
ldloc.1 <null>
callvirt System.Byte[] Stub.StubConfig::get_IVBytes()
call System.Byte[] Stub.Program::DecryptPayload(System.Byte[],System.Byte[],System.Byte[])
stloc.s V_6
ldloc.1 <null>
callvirt System.Boolean Stub.StubConfig::get_InMemory()
brtrue.s IL_00E6: ldloc.s V_6
ldloc.s V_6
ldloc.1 <null>
callvirt System.String Stub.StubConfig::get_OriginalFileName()
ldarg.0 <null>
call System.Int32 Stub.Program::ExecuteFromDisk(System.Byte[],System.String,System.String[])
br.s IL_00F4: call System.Void Stub.Decoy::Kill()
ldloc.s V_6
ldloc.1 <null>
callvirt System.String Stub.StubConfig::get_OriginalFileName()
ldarg.0 <null>
call System.Int32 Stub.Program::ExecuteManaged(System.Byte[],System.String,System.String[])
call System.Void Stub.Decoy::Kill()
stloc.s V_5
leave.s IL_011A: ldloc.s V_5
stloc.s V_7
ldstr Error
ldloc.s V_7
callvirt System.String System.Exception::get_Message()
call System.Void Stub.Program::ShowError(System.String,System.String)
call System.Void Stub.Decoy::Kill()
ldc.i4.1 <null>
stloc.s V_5
leave.s IL_011A: ldloc.s V_5
ldloc.s V_5
ret <null>
|
| Info |
PE Detect: PeReader OK (file layout) |
| Info |
Overlay extracted: Overlay_d8355c6c.bin (1624686 bytes) |
| Info |
|
| Module Name |
|
| Full Name |
|
| EntryPoint |
System.Int32 Stub.Program::Main(System.String[]) |
| Scope Name |
|
| Scope Type |
|
| Kind |
|
| Runtime Version |
|
| Tables Header Version |
|
| WinMD Version |
|
| Assembly Name |
|
| Assembly Version |
|
| Assembly Culture |
|
| Has PublicKey |
|
| PublicKey Token |
|
| Target Framework |
.NETFramework,Version=v4.8 |
| Total Strings |
|
| Main Method |
System.Int32 Stub.Program::Main(System.String[]) |
| Main IL Instruction Count |
|
| Main IL |
ldstr SYSRUNTIME_CTX
call System.String System.Environment::GetEnvironmentVariable(System.String)
dup <null>
brtrue.s IL_0013: stloc.0
pop <null>
ldstr
stloc.0 <null>
ldloc.0 <null>
ldstr d3c0y
call System.Boolean System.String::op_Equality(System.String,System.String)
brfalse.s IL_0029: ldloc.0
ldc.i4.m1 <null>
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldc.i4.0 <null>
ret <null>
ldloc.0 <null>
ldstr r3a1
call System.Boolean System.String::op_Inequality(System.String,System.String)
brfalse.s IL_0065: call System.Void Stub.Program::AntiSandboxDelay()
ldc.i4.0 <null>
stloc.3 <null>
call System.ValueTuple`2<Stub.StubConfig,System.Byte[]> Stub.Program::ReadFromOverlay()
ldfld Stub.StubConfig System.ValueTuple`2<Stub.StubConfig,System.Byte[]>::Item1
callvirt System.Boolean Stub.StubConfig::get_EnableStealthCopy()
stloc.3 <null>
leave.s IL_004D: ldloc.3
pop <null>
leave.s IL_004D: ldloc.3
ldloc.3 <null>
brfalse.s IL_0056: ldstr "SYSRUNTIME_CTX"
call System.Int32 Stub.Program::RelaunchWithRandomName()
ret <null>
ldstr SYSRUNTIME_CTX
ldstr r3a1
call System.Void System.Environment::SetEnvironmentVariable(System.String,System.String)
call System.Void Stub.Program::AntiSandboxDelay()
call System.ValueTuple`2<Stub.StubConfig,System.Byte[]> Stub.Program::ReadFromOverlay()
dup <null>
ldfld Stub.StubConfig System.ValueTuple`2<Stub.StubConfig,System.Byte[]>::Item1
stloc.1 <null>
ldfld System.Byte[] System.ValueTuple`2<Stub.StubConfig,System.Byte[]>::Item2
stloc.2 <null>
leave.s IL_0099: ldloc.1
stloc.s V_4
ldstr Load Error
ldloc.s V_4
callvirt System.String System.Exception::get_Message()
call System.Void Stub.Program::ShowError(System.String,System.String)
ldc.i4.1 <null>
stloc.s V_5
leave IL_011A: ldloc.s V_5
ldloc.1 <null>
callvirt System.Boolean Stub.StubConfig::get_EnableGuard()
brfalse.s IL_00AC: ldloc.1
ldloc.1 <null>
call System.Void Stub.Guard::set_Config(Stub.StubConfig)
call System.Void Stub.Guard::StartMonitoring()
ldloc.1 <null>
callvirt System.Boolean Stub.StubConfig::get_EnableDecoy()
brfalse.s IL_00B9: nop
call System.Void Stub.Decoy::Spawn()
nop <null>
ldloc.2 <null>
ldloc.1 <null>
callvirt System.Byte[] Stub.StubConfig::get_KeyBytes()
ldloc.1 <null>
callvirt System.Byte[] Stub.StubConfig::get_IVBytes()
call System.Byte[] Stub.Program::DecryptPayload(System.Byte[],System.Byte[],System.Byte[])
stloc.s V_6
ldloc.1 <null>
callvirt System.Boolean Stub.StubConfig::get_InMemory()
brtrue.s IL_00E6: ldloc.s V_6
ldloc.s V_6
ldloc.1 <null>
callvirt System.String Stub.StubConfig::get_OriginalFileName()
ldarg.0 <null>
call System.Int32 Stub.Program::ExecuteFromDisk(System.Byte[],System.String,System.String[])
br.s IL_00F4: call System.Void Stub.Decoy::Kill()
ldloc.s V_6
ldloc.1 <null>
callvirt System.String Stub.StubConfig::get_OriginalFileName()
ldarg.0 <null>
call System.Int32 Stub.Program::ExecuteManaged(System.Byte[],System.String,System.String[])
call System.Void Stub.Decoy::Kill()
stloc.s V_5
leave.s IL_011A: ldloc.s V_5
stloc.s V_7
ldstr Error
ldloc.s V_7
callvirt System.String System.Exception::get_Message()
call System.Void Stub.Program::ShowError(System.String,System.String)
call System.Void Stub.Decoy::Kill()
ldc.i4.1 <null>
stloc.s V_5
leave.s IL_011A: ldloc.s V_5
ldloc.s V_5
ret <null>
|