Symbol Obfuscation Score
|
Hash | Hash Value |
|---|---|
| MD5 | e164d44d5f7fd734a56464f573807c4a
|
| Sha1 | 5bde72588e7a9721185e00d978c104d61ca389d3
|
| Sha256 | 853cfdf61e9f6098348242d11e4cb581ed9bfe8f960fc2f2fd7ea93e5c9e1578
|
| Sha384 | 1529aaee13f06b6b75681400dde51c2b870c3219c8f74260a3ac78a7e29ecc6afed58e748ada13223d21586aad600de0
|
| Sha512 | 72186987a700dd2ccb89bfead0741ab626c5d20d4f69d0926f980ab4e3c8187f16270185ff0cb49ed107a0c0d2ee98e0c453f883b613a4ecd26bfebaf70108a1
|
| SSDeep | 24576:RXcrQ8SKxJzck+7eWBRwRR16zA0KKm77yviUSQaZaOwI55l2S62r9cGW/yFoBkkj:RXcrQKTYj77wRGKKm77LrwCB6hqany
|
| TLSH | 77850251B7F98117F2BF2BB9A8B304064B77FA539A36C79E0948905C2EA3740DE50367
|
PeID
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader FAIL, AsmResolver Mapped OK |
| Info | Remap: Mapped -> FileLayout (RAM only) as [Rebuild from dump]_45438263.exe |
| Module Name | Client.exe |
| Full Name | Client.exe |
| EntryPoint | System.Void cirgrikuewftd.YLPdn45jZpfeOrUsaCiGPyN2GC8af::Main() |
| Scope Name | Client.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Client |
| Assembly Version | 1.7.4.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 1511 |
| Main Method | System.Void cirgrikuewftd.YLPdn45jZpfeOrUsaCiGPyN2GC8af::Main() |
| Main IL Instruction Count | 11 |
| Main IL | ldc.i4 3072 call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType) ldc.i4.2 <null> call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode) call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) call System.Void cirgrikuewftd.YLPdn45jZpfeOrUsaCiGPyN2GC8af::EOZuTxYOBr() newobj System.Void cirgrikuewftd.TjRjwtzcFYhWvzRu7CiLn4az6Rznj::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null> |
| Module Name | Client.exe |
| Full Name | Client.exe |
| EntryPoint | System.Void cirgrikuewftd.YLPdn45jZpfeOrUsaCiGPyN2GC8af::Main() |
| Scope Name | Client.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Client |
| Assembly Version | 1.7.4.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 1511 |
| Main Method | System.Void cirgrikuewftd.YLPdn45jZpfeOrUsaCiGPyN2GC8af::Main() |
| Main IL Instruction Count | 11 |
| Main IL | ldc.i4 3072 call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType) ldc.i4.2 <null> call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode) call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) call System.Void cirgrikuewftd.YLPdn45jZpfeOrUsaCiGPyN2GC8af::EOZuTxYOBr() newobj System.Void cirgrikuewftd.TjRjwtzcFYhWvzRu7CiLn4az6Rznj::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) ret <null> |
|
Name0 | Value |
|---|---|
| PE Layout | MemoryMapped (process dump suspected) |
| PE Layout | MemoryMapped (process dump suspected) |
|
Name0 | Value | Location |
|---|---|---|
| PE Layout | MemoryMapped (process dump suspected) |
e164d44d5f7fd734a56464f573807c4a |
| PE Layout | MemoryMapped (process dump suspected) |
e164d44d5f7fd734a56464f573807c4a > [Rebuild from dump]_45438263.exe |