Symbol Ofbuscation Score
|
Hash | Hash Value |
|---|---|
| MD5 | f885ff5c50df983554fea57ed9e7b7a5
|
| Sha1 | 7681ce69c19b5e543ff43cae0bb4de6e78fe272e
|
| Sha256 | c54bd7c3ec3b9183ac28dec038c43463b770ac78557aca0abd10e9620990108a
|
| Sha384 | 3edd9c9a388e27f4c05f020556c18ce8fadbff5b0aa11d3890914921597b593170ae557168d76d44069eb4f40ce7b18e
|
| Sha512 | 3255342bbbb0d1ca656790c2508c6c3e9308ea29f33eeb7c64d0e641d694bbe1050070fc7f893127fe485d0be54a4a093db7c13eabbba85554cfeaae744865fc
|
| SSDeep | 49152:z3TTivxo5bkbOahc1LkrzzifkztavdBHgW6wk5Ayi9r/N5P:z3PKxKkbl+kbw
|
| TLSH | 09F54B40AFE8CE1BE1BF6775A4B2001157F1E549E722CB8B5654A1BC2DA37009E463BF
|
PeID
|
Name0 | Value |
|---|---|
| Module Name | Microsoft.exe |
| Full Name | Microsoft.exe |
| EntryPoint | System.Void Client.Program::Main(System.String[]) |
| Scope Name | Microsoft.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Microsoft |
| Assembly Version | 6.1.2.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 12571 |
| Main Method | System.Void Client.Program::Main(System.String[]) |
| Main IL Instruction Count | 134 |
| Main IL | ldarg.0 <null> ldlen <null> brtrue IL_0011: ldarg.0 ldstr br IL_0018: stloc.0 ldarg.0 <null> ldc.i4.0 <null> ldelem System.String stloc.0 <null> call System.Boolean Client.Helper.Methods::IsAdmin() brtrue IL_003D: call System.Boolean Client.Helper.MutexControl::CreateMutex() ldloc.0 <null> ldstr --flag call System.Boolean System.String::op_Equality(System.String,System.String) brfalse IL_003D: call System.Boolean Client.Helper.MutexControl::CreateMutex() call System.Void Client.Program::ForceGetAdminAccess() br IL_004D: ldc.i4.s 26 call System.Boolean Client.Helper.MutexControl::CreateMutex() brtrue IL_004D: ldc.i4.s 26 ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr 7n5rJCiEX08cdKRQsT6vxkbuaZ call System.String System.IO.Path::Combine(System.String,System.String) call System.IO.DirectoryInfo System.IO.Directory::CreateDirectory(System.String) pop <null> ldc.i4.1 <null> call System.Void System.Net.ServicePointManager::set_Expect100Continue(System.Boolean) ldc.i4 3072 call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType) ldc.i4 9999 call System.Void System.Net.ServicePointManager::set_DefaultConnectionLimit(System.Int32) ldc.i4.0 <null> stloc.1 <null> br IL_0093: ldloc.1 ldc.i4 1000 call System.Void System.Threading.Thread::Sleep(System.Int32) ldloc.1 <null> ldc.i4.1 <null> add <null> stloc.1 <null> ldloc.1 <null> ldsfld System.String Client.Settings::De_lay call System.Int32 System.Convert::ToInt32(System.String) blt.s IL_0085: ldc.i4 1000 call System.Boolean Client.Settings::InitializeSettings() brtrue IL_00B0: call System.Void Client.Helper.SetRegistry::InitRegistry() ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) call System.Void Client.Helper.SetRegistry::InitRegistry() ldsfld System.String Client.Settings::An_ti call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_00C9: leave IL_00D4 call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis() leave IL_00D4: call System.Void Client.Helper.A::B() pop <null> leave IL_00D4: call System.Void Client.Helper.A::B() call System.Void Client.Helper.A::B() ldsfld System.String Client.Settings::Anti_Process call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_00ED: leave IL_00F8 call System.Void Client.Helper.AntiProcess::StartBlock() leave IL_00F8: nop pop <null> leave IL_00F8: nop nop <null> ldsfld System.String Client.Settings::Enable_Clipper call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_0169: leave IL_0174 ldsfld System.Collections.Generic.Dictionary`2<System.String,System.String> Finder.Config::ClipperAddresses ldstr btc ldsfld System.String Client.Settings::Clipper_BTC callvirt System.Void System.Collections.Generic.Dictionary`2<System.String,System.String>::set_Item(System.String,System.String) ldsfld System.Collections.Generic.Dictionary`2<System.String,System.String> Finder.Config::ClipperAddresses ldstr eth ldsfld System.String Client.Settings::Clipper_ETH callvirt System.Void System.Collections.Generic.Dictionary`2<System.String,System.String>::set_Item(System.String,System.String) ldsfld System.Collections.Generic.Dictionary`2<System.String,System.String> Finder.Config::ClipperAddresses ldstr ltc ldsfld System.String Client.Settings::Clipper_LTC callvirt System.Void System.Collections.Generic.Dictionary`2<System.String,System.String>::set_Item(System.String,System.String) ldsfld System.Collections.Generic.Dictionary`2<System.String,System.String> Finder.Config::ClipperAddresses ldstr bch ldsfld System.String Client.Settings::Clipper_BCH callvirt System.Void System.Collections.Generic.Dictionary`2<System.String,System.String>::set_Item(System.String,System.String) ldsfld System.Threading.Thread Finder.Helpers.ClipboardManager::MainThread dup <null> ldc.i4.0 <null> callvirt System.Void System.Threading.Thread::SetApartmentState(System.Threading.ApartmentState) callvirt System.Void System.Threading.Thread::Start() leave IL_0174: nop pop <null> leave IL_0174: nop nop <null> ldsfld System.String Client.Settings::BS_OD call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_0193: leave IL_019E call System.Boolean Client.Helper.Methods::IsAdmin() brfalse IL_0193: leave IL_019E call System.Void Client.Helper.ProcessCritical::Set() leave IL_019E: nop pop <null> leave IL_019E: nop nop <null> ldsfld System.String Client.Settings::In_stall call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_01B3: leave IL_01BE call System.Void Client.Install.NormalStartup::Install() leave IL_01BE: call System.Void Client.Helper.Methods::PreventSleep() pop <null> leave IL_01BE: call System.Void Client.Helper.Methods::PreventSleep() call System.Void Client.Helper.Methods::PreventSleep() call System.Boolean Client.Helper.Methods::IsAdmin() brfalse IL_01D2: leave IL_01DD call System.Void Client.Helper.Methods::ClearSetting() leave IL_01DD: ldsfld System.Threading.ThreadStart Client.Program/<>c::<>9__2_0 pop <null> leave IL_01DD: ldsfld System.Threading.ThreadStart Client.Program/<>c::<>9__2_0 ldsfld System.Threading.ThreadStart Client.Program/<>c::<>9__2_0 dup <null> brtrue IL_01FF: newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart) pop <null> ldsfld Client.Program/<>c Client.Program/<>c::<>9 ldftn System.Void Client.Program/<>c::<Main>b__2_0() newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Threading.ThreadStart Client.Program/<>c::<>9__2_0 newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart) call System.Void System.Threading.Thread::Start() call System.IntPtr Client.Features.KeyLog.Keylogger::SetHook() pop <null> call System.Void System.Windows.Forms.Application::Run() ret <null> |
| Module Name | Microsoft.exe |
| Full Name | Microsoft.exe |
| EntryPoint | System.Void Client.Program::Main(System.String[]) |
| Scope Name | Microsoft.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Microsoft |
| Assembly Version | 6.1.2.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 12571 |
| Main Method | System.Void Client.Program::Main(System.String[]) |
| Main IL Instruction Count | 134 |
| Main IL | ldarg.0 <null> ldlen <null> brtrue IL_0011: ldarg.0 ldstr br IL_0018: stloc.0 ldarg.0 <null> ldc.i4.0 <null> ldelem System.String stloc.0 <null> call System.Boolean Client.Helper.Methods::IsAdmin() brtrue IL_003D: call System.Boolean Client.Helper.MutexControl::CreateMutex() ldloc.0 <null> ldstr --flag call System.Boolean System.String::op_Equality(System.String,System.String) brfalse IL_003D: call System.Boolean Client.Helper.MutexControl::CreateMutex() call System.Void Client.Program::ForceGetAdminAccess() br IL_004D: ldc.i4.s 26 call System.Boolean Client.Helper.MutexControl::CreateMutex() brtrue IL_004D: ldc.i4.s 26 ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr 7n5rJCiEX08cdKRQsT6vxkbuaZ call System.String System.IO.Path::Combine(System.String,System.String) call System.IO.DirectoryInfo System.IO.Directory::CreateDirectory(System.String) pop <null> ldc.i4.1 <null> call System.Void System.Net.ServicePointManager::set_Expect100Continue(System.Boolean) ldc.i4 3072 call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType) ldc.i4 9999 call System.Void System.Net.ServicePointManager::set_DefaultConnectionLimit(System.Int32) ldc.i4.0 <null> stloc.1 <null> br IL_0093: ldloc.1 ldc.i4 1000 call System.Void System.Threading.Thread::Sleep(System.Int32) ldloc.1 <null> ldc.i4.1 <null> add <null> stloc.1 <null> ldloc.1 <null> ldsfld System.String Client.Settings::De_lay call System.Int32 System.Convert::ToInt32(System.String) blt.s IL_0085: ldc.i4 1000 call System.Boolean Client.Settings::InitializeSettings() brtrue IL_00B0: call System.Void Client.Helper.SetRegistry::InitRegistry() ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) call System.Void Client.Helper.SetRegistry::InitRegistry() ldsfld System.String Client.Settings::An_ti call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_00C9: leave IL_00D4 call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis() leave IL_00D4: call System.Void Client.Helper.A::B() pop <null> leave IL_00D4: call System.Void Client.Helper.A::B() call System.Void Client.Helper.A::B() ldsfld System.String Client.Settings::Anti_Process call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_00ED: leave IL_00F8 call System.Void Client.Helper.AntiProcess::StartBlock() leave IL_00F8: nop pop <null> leave IL_00F8: nop nop <null> ldsfld System.String Client.Settings::Enable_Clipper call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_0169: leave IL_0174 ldsfld System.Collections.Generic.Dictionary`2<System.String,System.String> Finder.Config::ClipperAddresses ldstr btc ldsfld System.String Client.Settings::Clipper_BTC callvirt System.Void System.Collections.Generic.Dictionary`2<System.String,System.String>::set_Item(System.String,System.String) ldsfld System.Collections.Generic.Dictionary`2<System.String,System.String> Finder.Config::ClipperAddresses ldstr eth ldsfld System.String Client.Settings::Clipper_ETH callvirt System.Void System.Collections.Generic.Dictionary`2<System.String,System.String>::set_Item(System.String,System.String) ldsfld System.Collections.Generic.Dictionary`2<System.String,System.String> Finder.Config::ClipperAddresses ldstr ltc ldsfld System.String Client.Settings::Clipper_LTC callvirt System.Void System.Collections.Generic.Dictionary`2<System.String,System.String>::set_Item(System.String,System.String) ldsfld System.Collections.Generic.Dictionary`2<System.String,System.String> Finder.Config::ClipperAddresses ldstr bch ldsfld System.String Client.Settings::Clipper_BCH callvirt System.Void System.Collections.Generic.Dictionary`2<System.String,System.String>::set_Item(System.String,System.String) ldsfld System.Threading.Thread Finder.Helpers.ClipboardManager::MainThread dup <null> ldc.i4.0 <null> callvirt System.Void System.Threading.Thread::SetApartmentState(System.Threading.ApartmentState) callvirt System.Void System.Threading.Thread::Start() leave IL_0174: nop pop <null> leave IL_0174: nop nop <null> ldsfld System.String Client.Settings::BS_OD call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_0193: leave IL_019E call System.Boolean Client.Helper.Methods::IsAdmin() brfalse IL_0193: leave IL_019E call System.Void Client.Helper.ProcessCritical::Set() leave IL_019E: nop pop <null> leave IL_019E: nop nop <null> ldsfld System.String Client.Settings::In_stall call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_01B3: leave IL_01BE call System.Void Client.Install.NormalStartup::Install() leave IL_01BE: call System.Void Client.Helper.Methods::PreventSleep() pop <null> leave IL_01BE: call System.Void Client.Helper.Methods::PreventSleep() call System.Void Client.Helper.Methods::PreventSleep() call System.Boolean Client.Helper.Methods::IsAdmin() brfalse IL_01D2: leave IL_01DD call System.Void Client.Helper.Methods::ClearSetting() leave IL_01DD: ldsfld System.Threading.ThreadStart Client.Program/<>c::<>9__2_0 pop <null> leave IL_01DD: ldsfld System.Threading.ThreadStart Client.Program/<>c::<>9__2_0 ldsfld System.Threading.ThreadStart Client.Program/<>c::<>9__2_0 dup <null> brtrue IL_01FF: newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart) pop <null> ldsfld Client.Program/<>c Client.Program/<>c::<>9 ldftn System.Void Client.Program/<>c::<Main>b__2_0() newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Threading.ThreadStart Client.Program/<>c::<>9__2_0 newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart) call System.Void System.Threading.Thread::Start() call System.IntPtr Client.Features.KeyLog.Keylogger::SetHook() pop <null> call System.Void System.Windows.Forms.Application::Run() ret <null> |
|
Name0 | Value |
|---|---|
| PDB Path | C:\Users\NEMESIS\Desktop\BigEye Final_2025_05_27 Fixed Scale\BigEye Final_2025_05_27 Fixed Scale\Client\Resources\SetDpi.pdb |
| PDB Path | D:\Working Projects\Active Project\Venom Project\Venom RAT + HVNC 2025 Updates\Venom hVNC Final_2025_07_12 Released v6.1.1\HVNCDll\obj\Release\hvnc.pdb |
|
Name0 | Value | Location |
|---|---|---|
| PDB Path | C:\Users\NEMESIS\Desktop\BigEye Final_2025_05_27 Fixed Scale\BigEye Final_2025_05_27 Fixed Scale\Client\Resources\SetDpi.pdb |
f885ff5c50df983554fea57ed9e7b7a5 > .Net Resources > Client.Properties.Resources.resources > SetDpi |
| PDB Path | D:\Working Projects\Active Project\Venom Project\Venom RAT + HVNC 2025 Updates\Venom hVNC Final_2025_07_12 Released v6.1.1\HVNCDll\obj\Release\hvnc.pdb |
f885ff5c50df983554fea57ed9e7b7a5 > .Net Resources > Client.Properties.Resources.resources > hvnc |