Suspicious
Suspect

f4aaf1590b67202a53d0cb1e5cbb14ac

PE Executable
|
MD5: f4aaf1590b67202a53d0cb1e5cbb14ac
|
Size: 1.22 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
f4aaf1590b67202a53d0cb1e5cbb14ac
Sha1
dfc3845b5c49c6e10db9c18996c14efcdf38d56d
Sha256
224e0b0c7d63021746160451950f5a4dfdad895be2c57ad05863ec54c1e774b5
Sha384
c58930fe4877b7436ceb4fb8c1063c3f16d4bc893caa0d3d7be9b6abe1b144a7d8767c657a0b15b5bf944a02951469bf
Sha512
46354efdb76f63c31aa1ca3e03eeac4b838cad6d6e37304891149406f4272bf94aac71c16ee4c3dcf6058a39eeb9d77e3c08d13bd1563e99adda5d2de78806ef
SSDeep
24576:ZaiZcstwoCiI6rmzd3LXvlbSHQonCK/GWvCM:ZbxwoLIEmZbXdbSw1s
TLSH
9545E03627E55B94F0FECB34E278004487F1B91BD622E7AE2D4811ED8E21B469A53773

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Hjk9x2oQK.g.resources
Hjk9x2oQK.Resources.resources
b386cecdeb078a.Resources.resources
7bc64cbc0
[NBF]root.Data
7bc64cbc1
[NBF]root.Data
7bc64cbc10
[NBF]root.Data
7bc64cbc11
[NBF]root.Data
7bc64cbc12
[NBF]root.Data
7bc64cbc13
[NBF]root.Data
7bc64cbc14
[NBF]root.Data
7bc64cbc15
[NBF]root.Data
7bc64cbc16
[NBF]root.Data
7bc64cbc17
[NBF]root.Data
7bc64cbc18
[NBF]root.Data
7bc64cbc19
[NBF]root.Data
7bc64cbc2
[NBF]root.Data
7bc64cbc20
[NBF]root.Data
7bc64cbc21
[NBF]root.Data
7bc64cbc22
[NBF]root.Data
7bc64cbc23
[NBF]root.Data
7bc64cbc24
[NBF]root.Data
7bc64cbc25
[NBF]root.Data
7bc64cbc26
[NBF]root.Data
7bc64cbc27
[NBF]root.Data
7bc64cbc28
[NBF]root.Data
7bc64cbc29
[NBF]root.Data
7bc64cbc3
[NBF]root.Data
7bc64cbc30
[NBF]root.Data
7bc64cbc31
[NBF]root.Data
7bc64cbc32
[NBF]root.Data
7bc64cbc33
[NBF]root.Data
7bc64cbc34
[NBF]root.Data
7bc64cbc35
[NBF]root.Data
7bc64cbc36
[NBF]root.Data
7bc64cbc37
[NBF]root.Data
7bc64cbc38
[NBF]root.Data
7bc64cbc39
[NBF]root.Data
7bc64cbc4
[NBF]root.Data
7bc64cbc40
[NBF]root.Data
7bc64cbc41
[NBF]root.Data
7bc64cbc42
[NBF]root.Data
7bc64cbc5
[NBF]root.Data
7bc64cbc6
[NBF]root.Data
7bc64cbc7
[NBF]root.Data
7bc64cbc8
[NBF]root.Data
7bc64cbc9
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Hjk9x2oQK

Full Name

Hjk9x2oQK

EntryPoint

System.Void Hjk9x2oQK.Be0bx8::qw9LPed7t()

Scope Name

Hjk9x2oQK

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Hjk9x2oQK

Assembly Version

2.15.6.169

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1341

Main Method

System.Void Hjk9x2oQK.Be0bx8::qw9LPed7t()

Main IL Instruction Count

338

Main IL

nop <null> nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> call System.DateTime System.DateTime::get_Now() stloc.0 <null> ldc.i4 10001 newarr System.Int32 stloc.1 <null> ldloc.1 <null> ldlen <null> conv.i4 <null> ldc.i4.1 <null> sub.ovf <null> stloc.s V_14 ldc.i4.0 <null> stloc.s V_15 br.s IL_003A: ldloc.s V_15 ldloc.1 <null> ldloc.s V_15 ldloc.s V_15 ldc.i4.s 31 mul.ovf <null> ldc.i4 10000 rem <null> stelem.i4 <null> ldloc.s V_15 ldc.i4.1 <null> add.ovf <null> stloc.s V_15 ldloc.s V_15 ldloc.s V_14 ble.s IL_0025: ldloc.1 ldloc.1 <null> call System.Void System.Array::Sort<System.Int32>(System.Int32[]) nop <null> ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr SystemTools ldstr cache.cfg call System.String System.IO.Path::Combine(System.String,System.String,System.String) stloc.2 <null> ldc.r8 24 call System.Double System.Math::Abs(System.Double) call System.Double System.Math::Round(System.Double) conv.ovf.i4 <null> stloc.3 <null> ldloc.3 <null> call System.Object Hjk9x2oQK.Pf8d3AgjtoT0J/Kwa3ib2NRkk.zYx1ai9L::7jrNB1anzF0(System.Int32) castclass System.Object[] stloc.s V_4 ldstr resources/13 ldc.i4.0 <null> newarr System.Object call System.String System.String::Format(System.String,System.Object[]) stloc.s V_5 ldloc.s V_4 ldc.i4.0 <null> ldloc.s V_5 stelem.ref <null> ldloc.s V_4 ldc.i4.2 <null> ldloc.s V_4 ldc.i4.0 <null> ldelem.ref <null> call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object) call System.Byte[] Hjk9x2oQK.Kp3ifXo19::xz2Z7BtoLst(System.String) stelem.ref <null> call System.String System.IO.Path::GetTempPath() stloc.s V_6 ldloc.s V_6 call System.Boolean System.IO.Directory::Exists(System.String) ldc.i4.0 <null> ceq <null> stloc.s V_16 ldloc.s V_16 brfalse.s IL_00C9: ldc.i4.s 100 ldloc.s V_6 call System.IO.DirectoryInfo System.IO.Directory::CreateDirectory(System.String) pop <null> ldc.i4.s 100 stloc.s V_7 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newobj System.Void System.Int32[0...,0...]::.ctor(System.Int32,System.Int32) stloc.s V_8 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newobj System.Void System.Int32[0...,0...]::.ctor(System.Int32,System.Int32) stloc.s V_9 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newobj System.Void System.Int32[0...,0...]::.ctor(System.Int32,System.Int32) stloc.s V_10 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> stloc.s V_17 ldc.i4.0 <null> stloc.s V_18 br.s IL_014E: ldloc.s V_18 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> stloc.s V_19 ldc.i4.0 <null> stloc.s V_20 br.s IL_0142: ldloc.s V_20 ldloc.s V_8 ldloc.s V_18 ldloc.s V_20 ldloc.s V_18 ldloc.s V_20 add.ovf <null> call System.Void System.Int32[0...,0...]::Set(System.Int32,System.Int32,System.Int32) ldloc.s V_9 ldloc.s V_18 ldloc.s V_20 ldloc.s V_18 ldloc.s V_20 mul.ovf <null> call System.Void System.Int32[0...,0...]::Set(System.Int32,System.Int32,System.Int32) ldloc.s V_20 ldc.i4.1 <null> add.ovf <null> stloc.s V_20 ldloc.s V_20 ldloc.s V_19 ble.s IL_011C: ldloc.s V_8 ldloc.s V_18 ldc.i4.1 <null> add.ovf <null> stloc.s V_18 ldloc.s V_18 ldloc.s V_17 ble.s IL_0111: ldloc.s V_7 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> stloc.s V_21 ldc.i4.0 <null> stloc.s V_22 br.s IL_01C9: ldloc.s V_22 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> stloc.s V_23 ldc.i4.0 <null> stloc.s V_24 br.s IL_01BD: ldloc.s V_24 ldloc.s V_10 ldloc.s V_22 ldloc.s V_24 ldc.i4.0 <null> call System.Void System.Int32[0...,0...]::Set(System.Int32,System.Int32,System.Int32) ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> stloc.s V_25 ldc.i4.0 <null> stloc.s V_26 br.s IL_01B1: ldloc.s V_26 ldloc.s V_10 ldloc.s V_22 ldloc.s V_24 call System.Int32& System.Int32[0...,0...]::Address(System.Int32,System.Int32) dup <null> stloc.s V_27 ldloc.s V_27 ldind.i4 <null> ldloc.s V_8 ldloc.s V_22 ldloc.s V_26 call System.Int32 System.Int32[0...,0...]::Get(System.Int32,System.Int32) ldloc.s V_9 ldloc.s V_26 ldloc.s V_24 call System.Int32 System.Int32[0...,0...]::Get(System.Int32,System.Int32) mul.ovf <null> add.ovf <null> stind.i4 <null> ldloc.s V_26 ldc.i4.1 <null> add.ovf <null> stloc.s V_26 ldloc.s V_26 ldloc.s V_25 ble.s IL_0181: ldloc.s V_10 ldloc.s V_24 ldc.i4.1 <null> add.ovf <null> stloc.s V_24 ldloc.s V_24 ldloc.s V_23 ble.s IL_016A: ldloc.s V_10 ldloc.s V_22 ldc.i4.1 <null> add.ovf <null> stloc.s V_22 ldloc.s V_22 ldloc.s V_21 ble.s IL_015F: ldloc.s V_7 ldloc.s V_4 ldc.i4.3 <null> ldloc.s V_4 ldc.i4.2 <null> ldelem.ref <null> castclass System.Byte[] call System.Byte[] Hjk9x2oQK.2czJdcQ8/4fiEs2.yRe80zqJkB9j/md3HFbq6aJ.3oxPdG::wJg47rjBk5RdY(System.Byte[]) stelem.ref <null> ldloc.s V_10 ldc.i4.s 50 ldc.i4.s 50 call System.Int32 System.Int32[0...,0...]::Get(System.Int32,System.Int32) ldc.i4.s 100 rem <null> conv.r8 <null> ldc.r8 100 div <null> stloc.s V_11 ldloc.s V_11 ldc.r8 0.95 clt <null> stloc.s V_12 ldc.r8 0 stloc.s V_13 ldc.i4.0 <null> stloc.s V_28 ldloc.s V_13 ldc.r8 -1 ldloc.s V_28 conv.r8 <null> call System.Double System.Math::Pow(System.Double,System.Double) ldc.i4.2 <null> ldloc.s V_28 mul.ovf <null> ldc.i4.1 <null> add.ovf <null> conv.r8 <null> div <null> add <null> stloc.s V_13 ldloc.s V_28 ldc.i4.1 <null> add.ovf <null> stloc.s V_28 ldloc.s V_28 ldc.i4 1000000 ble.s IL_0219: ldloc.s V_13 ldloc.s V_13 ldc.r8 4 mul <null> stloc.s V_13 nop <null> ldstr SystemService call System.Boolean System.Diagnostics.EventLog::SourceExists(System.String) stloc.s V_29 ldloc.s V_29 brfalse.s IL_02AA: nop nop <null> ldstr Application newobj System.Void System.Diagnostics.EventLog::.ctor(System.String) stloc.s V_30 ldloc.s V_30 ldstr SystemService callvirt System.Void System.Diagnostics.EventLog::set_Source(System.String) nop <null> ldloc.s V_30 ldstr Module initialized. PI≈{0:F5} ldloc.s V_13 box System.Double call System.String System.String::Format(System.String,System.Object) ldc.i4.4 <null> callvirt System.Void System.Diagnostics.EventLog::WriteEntry(System.String,System.Diagnostics.EventLogEntryType) nop <null> leave.s IL_02A9: nop nop <null> ldloc.s V_30 brfalse.s IL_02A8: endfinally ldloc.s V_30 callvirt System.Void System.IDisposable::Dispose() nop <null> endfinally <null> nop <null> nop <null> leave.s IL_02BA: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_02BA: nop nop <null> ldstr L o a d ldloc.s V_4 ldc.i4.3 <null> ldelem.ref <null> call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) call System.Object Hjk9x2oQK.Be0bx8/Jn4nf0Kr3N.Jc4pi9c::7Figm9Xk0p(System.String,System.Object) pop <null> leave.s IL_02F2: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_31 nop <null> nop <null> leave.s IL_02EA: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_02EA: nop nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_02F2: nop nop <null> ret <null>

Module Name

Hjk9x2oQK

Full Name

Hjk9x2oQK

EntryPoint

System.Void Hjk9x2oQK.Be0bx8::qw9LPed7t()

Scope Name

Hjk9x2oQK

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Hjk9x2oQK

Assembly Version

2.15.6.169

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1341

Main Method

System.Void Hjk9x2oQK.Be0bx8::qw9LPed7t()

Main IL Instruction Count

338

Main IL

nop <null> nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> call System.DateTime System.DateTime::get_Now() stloc.0 <null> ldc.i4 10001 newarr System.Int32 stloc.1 <null> ldloc.1 <null> ldlen <null> conv.i4 <null> ldc.i4.1 <null> sub.ovf <null> stloc.s V_14 ldc.i4.0 <null> stloc.s V_15 br.s IL_003A: ldloc.s V_15 ldloc.1 <null> ldloc.s V_15 ldloc.s V_15 ldc.i4.s 31 mul.ovf <null> ldc.i4 10000 rem <null> stelem.i4 <null> ldloc.s V_15 ldc.i4.1 <null> add.ovf <null> stloc.s V_15 ldloc.s V_15 ldloc.s V_14 ble.s IL_0025: ldloc.1 ldloc.1 <null> call System.Void System.Array::Sort<System.Int32>(System.Int32[]) nop <null> ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr SystemTools ldstr cache.cfg call System.String System.IO.Path::Combine(System.String,System.String,System.String) stloc.2 <null> ldc.r8 24 call System.Double System.Math::Abs(System.Double) call System.Double System.Math::Round(System.Double) conv.ovf.i4 <null> stloc.3 <null> ldloc.3 <null> call System.Object Hjk9x2oQK.Pf8d3AgjtoT0J/Kwa3ib2NRkk.zYx1ai9L::7jrNB1anzF0(System.Int32) castclass System.Object[] stloc.s V_4 ldstr resources/13 ldc.i4.0 <null> newarr System.Object call System.String System.String::Format(System.String,System.Object[]) stloc.s V_5 ldloc.s V_4 ldc.i4.0 <null> ldloc.s V_5 stelem.ref <null> ldloc.s V_4 ldc.i4.2 <null> ldloc.s V_4 ldc.i4.0 <null> ldelem.ref <null> call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object) call System.Byte[] Hjk9x2oQK.Kp3ifXo19::xz2Z7BtoLst(System.String) stelem.ref <null> call System.String System.IO.Path::GetTempPath() stloc.s V_6 ldloc.s V_6 call System.Boolean System.IO.Directory::Exists(System.String) ldc.i4.0 <null> ceq <null> stloc.s V_16 ldloc.s V_16 brfalse.s IL_00C9: ldc.i4.s 100 ldloc.s V_6 call System.IO.DirectoryInfo System.IO.Directory::CreateDirectory(System.String) pop <null> ldc.i4.s 100 stloc.s V_7 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newobj System.Void System.Int32[0...,0...]::.ctor(System.Int32,System.Int32) stloc.s V_8 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newobj System.Void System.Int32[0...,0...]::.ctor(System.Int32,System.Int32) stloc.s V_9 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newobj System.Void System.Int32[0...,0...]::.ctor(System.Int32,System.Int32) stloc.s V_10 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> stloc.s V_17 ldc.i4.0 <null> stloc.s V_18 br.s IL_014E: ldloc.s V_18 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> stloc.s V_19 ldc.i4.0 <null> stloc.s V_20 br.s IL_0142: ldloc.s V_20 ldloc.s V_8 ldloc.s V_18 ldloc.s V_20 ldloc.s V_18 ldloc.s V_20 add.ovf <null> call System.Void System.Int32[0...,0...]::Set(System.Int32,System.Int32,System.Int32) ldloc.s V_9 ldloc.s V_18 ldloc.s V_20 ldloc.s V_18 ldloc.s V_20 mul.ovf <null> call System.Void System.Int32[0...,0...]::Set(System.Int32,System.Int32,System.Int32) ldloc.s V_20 ldc.i4.1 <null> add.ovf <null> stloc.s V_20 ldloc.s V_20 ldloc.s V_19 ble.s IL_011C: ldloc.s V_8 ldloc.s V_18 ldc.i4.1 <null> add.ovf <null> stloc.s V_18 ldloc.s V_18 ldloc.s V_17 ble.s IL_0111: ldloc.s V_7 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> stloc.s V_21 ldc.i4.0 <null> stloc.s V_22 br.s IL_01C9: ldloc.s V_22 ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> stloc.s V_23 ldc.i4.0 <null> stloc.s V_24 br.s IL_01BD: ldloc.s V_24 ldloc.s V_10 ldloc.s V_22 ldloc.s V_24 ldc.i4.0 <null> call System.Void System.Int32[0...,0...]::Set(System.Int32,System.Int32,System.Int32) ldloc.s V_7 ldc.i4.1 <null> sub.ovf <null> stloc.s V_25 ldc.i4.0 <null> stloc.s V_26 br.s IL_01B1: ldloc.s V_26 ldloc.s V_10 ldloc.s V_22 ldloc.s V_24 call System.Int32& System.Int32[0...,0...]::Address(System.Int32,System.Int32) dup <null> stloc.s V_27 ldloc.s V_27 ldind.i4 <null> ldloc.s V_8 ldloc.s V_22 ldloc.s V_26 call System.Int32 System.Int32[0...,0...]::Get(System.Int32,System.Int32) ldloc.s V_9 ldloc.s V_26 ldloc.s V_24 call System.Int32 System.Int32[0...,0...]::Get(System.Int32,System.Int32) mul.ovf <null> add.ovf <null> stind.i4 <null> ldloc.s V_26 ldc.i4.1 <null> add.ovf <null> stloc.s V_26 ldloc.s V_26 ldloc.s V_25 ble.s IL_0181: ldloc.s V_10 ldloc.s V_24 ldc.i4.1 <null> add.ovf <null> stloc.s V_24 ldloc.s V_24 ldloc.s V_23 ble.s IL_016A: ldloc.s V_10 ldloc.s V_22 ldc.i4.1 <null> add.ovf <null> stloc.s V_22 ldloc.s V_22 ldloc.s V_21 ble.s IL_015F: ldloc.s V_7 ldloc.s V_4 ldc.i4.3 <null> ldloc.s V_4 ldc.i4.2 <null> ldelem.ref <null> castclass System.Byte[] call System.Byte[] Hjk9x2oQK.2czJdcQ8/4fiEs2.yRe80zqJkB9j/md3HFbq6aJ.3oxPdG::wJg47rjBk5RdY(System.Byte[]) stelem.ref <null> ldloc.s V_10 ldc.i4.s 50 ldc.i4.s 50 call System.Int32 System.Int32[0...,0...]::Get(System.Int32,System.Int32) ldc.i4.s 100 rem <null> conv.r8 <null> ldc.r8 100 div <null> stloc.s V_11 ldloc.s V_11 ldc.r8 0.95 clt <null> stloc.s V_12 ldc.r8 0 stloc.s V_13 ldc.i4.0 <null> stloc.s V_28 ldloc.s V_13 ldc.r8 -1 ldloc.s V_28 conv.r8 <null> call System.Double System.Math::Pow(System.Double,System.Double) ldc.i4.2 <null> ldloc.s V_28 mul.ovf <null> ldc.i4.1 <null> add.ovf <null> conv.r8 <null> div <null> add <null> stloc.s V_13 ldloc.s V_28 ldc.i4.1 <null> add.ovf <null> stloc.s V_28 ldloc.s V_28 ldc.i4 1000000 ble.s IL_0219: ldloc.s V_13 ldloc.s V_13 ldc.r8 4 mul <null> stloc.s V_13 nop <null> ldstr SystemService call System.Boolean System.Diagnostics.EventLog::SourceExists(System.String) stloc.s V_29 ldloc.s V_29 brfalse.s IL_02AA: nop nop <null> ldstr Application newobj System.Void System.Diagnostics.EventLog::.ctor(System.String) stloc.s V_30 ldloc.s V_30 ldstr SystemService callvirt System.Void System.Diagnostics.EventLog::set_Source(System.String) nop <null> ldloc.s V_30 ldstr Module initialized. PI≈{0:F5} ldloc.s V_13 box System.Double call System.String System.String::Format(System.String,System.Object) ldc.i4.4 <null> callvirt System.Void System.Diagnostics.EventLog::WriteEntry(System.String,System.Diagnostics.EventLogEntryType) nop <null> leave.s IL_02A9: nop nop <null> ldloc.s V_30 brfalse.s IL_02A8: endfinally ldloc.s V_30 callvirt System.Void System.IDisposable::Dispose() nop <null> endfinally <null> nop <null> nop <null> leave.s IL_02BA: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_02BA: nop nop <null> ldstr L o a d ldloc.s V_4 ldc.i4.3 <null> ldelem.ref <null> call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) call System.Object Hjk9x2oQK.Be0bx8/Jn4nf0Kr3N.Jc4pi9c::7Figm9Xk0p(System.String,System.Object) pop <null> leave.s IL_02F2: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_31 nop <null> nop <null> leave.s IL_02EA: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_02EA: nop nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_02F2: nop nop <null> ret <null>

f4aaf1590b67202a53d0cb1e5cbb14ac (1.22 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Hjk9x2oQK.g.resources
Hjk9x2oQK.Resources.resources
b386cecdeb078a.Resources.resources
7bc64cbc0
[NBF]root.Data
7bc64cbc1
[NBF]root.Data
7bc64cbc10
[NBF]root.Data
7bc64cbc11
[NBF]root.Data
7bc64cbc12
[NBF]root.Data
7bc64cbc13
[NBF]root.Data
7bc64cbc14
[NBF]root.Data
7bc64cbc15
[NBF]root.Data
7bc64cbc16
[NBF]root.Data
7bc64cbc17
[NBF]root.Data
7bc64cbc18
[NBF]root.Data
7bc64cbc19
[NBF]root.Data
7bc64cbc2
[NBF]root.Data
7bc64cbc20
[NBF]root.Data
7bc64cbc21
[NBF]root.Data
7bc64cbc22
[NBF]root.Data
7bc64cbc23
[NBF]root.Data
7bc64cbc24
[NBF]root.Data
7bc64cbc25
[NBF]root.Data
7bc64cbc26
[NBF]root.Data
7bc64cbc27
[NBF]root.Data
7bc64cbc28
[NBF]root.Data
7bc64cbc29
[NBF]root.Data
7bc64cbc3
[NBF]root.Data
7bc64cbc30
[NBF]root.Data
7bc64cbc31
[NBF]root.Data
7bc64cbc32
[NBF]root.Data
7bc64cbc33
[NBF]root.Data
7bc64cbc34
[NBF]root.Data
7bc64cbc35
[NBF]root.Data
7bc64cbc36
[NBF]root.Data
7bc64cbc37
[NBF]root.Data
7bc64cbc38
[NBF]root.Data
7bc64cbc39
[NBF]root.Data
7bc64cbc4
[NBF]root.Data
7bc64cbc40
[NBF]root.Data
7bc64cbc41
[NBF]root.Data
7bc64cbc42
[NBF]root.Data
7bc64cbc5
[NBF]root.Data
7bc64cbc6
[NBF]root.Data
7bc64cbc7
[NBF]root.Data
7bc64cbc8
[NBF]root.Data
7bc64cbc9
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙