Suspicious
Suspect

ff617fc5d1968e2d95a7aec28cefac4a

PE Executable
|
MD5: ff617fc5d1968e2d95a7aec28cefac4a
|
Size: 701.44 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Very high

Hash
Hash Value
MD5
ff617fc5d1968e2d95a7aec28cefac4a
Sha1
29fd27e9b165631a8cf903166e75ec1e7d6df986
Sha256
e6bb646f56c9c4807ee6aa5d50101b0bc1240f748e6c9c12a3f673f2f828d10f
Sha384
1aca94d09945b6447a252c9ad8244a8a5fc742c69461bef647210f0c8f8fe5dc375432ea24ed9cd1b47547d23e8e12c7
Sha512
5ac76a1c16b6747612307bf49169d61fa783d40226c215b76fabf96d32c1491c5de1d0b71947e51e34af27a4fa6697b54211959fb02a2f8902532a71d5cee777
SSDeep
12288:iDaqcak6kuuk26BN+X4QG7MAB6J/zzBsdXGSQtTjJq/pV14J5cvTBg11EQ5rXH98:4agUK7MABYK2uxb4STBa5rXH9c7oI
TLSH
77E4CE621E567F48C63E0BB8C027098873F089539283D76B7EFD51F54AA3BC6CA17946

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Kezada.jeydaseba.bat
zNq9aq1H.Resources.resources
2928bc919ed12d.Resources.resources
228fa9c30
[NBF]root.Data
228fa9c31
[NBF]root.Data
228fa9c32
[NBF]root.Data
228fa9c33
[NBF]root.Data
228fa9c34
[NBF]root.Data
228fa9c35
[NBF]root.Data
228fa9c36
[NBF]root.Data
228fa9c37
[NBF]root.Data
228fa9c38
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

zNq9aq1H

Full Name

zNq9aq1H

EntryPoint

System.Void 9NsoGrt1.pXs8H/qYe29zRmnL.3tzLeWb8e5Yf::wc9To2W()

Scope Name

zNq9aq1H

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

zNq9aq1H

Assembly Version

7.19.27.279

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

0

Main Method

System.Void 9NsoGrt1.pXs8H/qYe29zRmnL.3tzLeWb8e5Yf::wc9To2W()

Main IL Instruction Count

322

Main IL

nop <null> ldc.r8 1 stloc.0 <null> ldloca.s V_1 initobj System.Int16 br.s IL_0015: ldc.i4.6 ldc.i4.6 <null> stloc.s V_24 ldloc.s V_24 switch dnlib.DotNet.Emit.Instruction[] br.s IL_005D: nop nop <null> nop <null> ldc.i4 1920045871 ldc.i4.6 <null> ldnull <null> call System.String 5Tsyc1QfMa2.A_j6bm0TnG::2cgWR3nxaZ(System.Int32,System.Int32,System.String) stloc.2 <null> ldloc.2 <null> stloc.3 <null> ldc.i4.1 <null> stloc.s V_13 ldc.i4.1 <null> stloc.s V_24 br.s IL_0018: ldloc.s V_24 ldloc.3 <null> call System.Collections.Generic.IEnumerable`1<System.Char> System.Linq.Enumerable::Reverse<System.Char>(System.Collections.Generic.IEnumerable`1<System.Char>) call System.Char[] System.Linq.Enumerable::ToArray<System.Char>(System.Collections.Generic.IEnumerable`1<System.Char>) newobj System.Void System.String::.ctor(System.Char[]) stloc.3 <null> ldloc.s V_13 ldc.i4.1 <null> add.ovf <null> stloc.s V_13 ldloc.s V_13 ldc.i4 10000 ble.s IL_009E: ldc.i4.1 ldc.i4.3 <null> stloc.s V_24 br IL_0018: ldloc.s V_24 ldc.i4.1 <null> br.s IL_0097: stloc.s V_24 ldloc.2 <null> ldloca.s V_4 call System.Boolean System.DateTime::TryParse(System.String,System.DateTime&) pop <null> ldtoken System.Int32 call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) callvirt System.Reflection.Assembly System.Type::get_Assembly() stloc.s V_5 ldloc.s V_5 nop <null> ldc.i8 3 ldtoken 9NsoGrt1.pXs8H/qTs7io0SPqi1c6.3Byxo5Jz9Hmgik call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) ldc.i4 2085448065 ldc.i4.2 <null> call System.String Bp3z2.tx5ZTbb92LqgWi/5MasRa0d.Wrk2nQ5k3tmGbe/oy2F3xMqA0incD.2LqprgG6S0::5tgTkYy0N6(System.Int64,System.Type,System.Int32,System.Int32) callvirt System.Type System.Reflection.Assembly::GetType(System.String) stloc.s V_6 ldc.i4.s 11 stloc.s V_24 br IL_0018: ldloc.s V_24 ldtoken System.Object call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) stloc.s V_7 ldloc.s V_6 ldc.i4.1 <null> newarr System.Type dup <null> ldc.i4.0 <null> ldloc.s V_7 stelem.ref <null> callvirt System.Type System.Type::MakeGenericType(System.Type[]) stloc.s V_8 ldc.i4.0 <null> stloc.s V_24 br IL_0018: ldloc.s V_24 ldloc.s V_8 call System.Object System.Activator::CreateInstance(System.Type) castclass System.Collections.Generic.List`1<System.Object> stloc.s V_9 ldloc.s V_9 call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() callvirt System.Void System.Collections.Generic.List`1<System.Object>::Add(System.Object) nop <null> ldc.i4.0 <null> conv.i8 <null> stloc.s V_10 ldc.i4.2 <null> stloc.s V_24 br IL_0018: ldloc.s V_24 ldc.i4.1 <null> conv.i8 <null> stloc.s V_11 ldc.i4.1 <null> stloc.s V_14 ldc.i4.s 12 stloc.s V_24 br IL_0018: ldloc.s V_24 ldloc.s V_10 ldloc.s V_11 add.ovf <null> stloc.s V_15 ldloc.s V_11 stloc.s V_10 ldloc.s V_15 stloc.s V_11 ldloc.s V_14 ldc.i4.1 <null> add.ovf <null> stloc.s V_14 ldc.i4.4 <null> stloc.s V_24 br IL_0018: ldloc.s V_24 ldloc.s V_14 ldc.i4.s 50 ble.s IL_0177: ldc.i4.s 12 ldc.i4.s 10 stloc.s V_24 br IL_0018: ldloc.s V_24 ldc.i4.s 12 br.s IL_0170: stloc.s V_24 ldloc.s V_9 callvirt System.Int32 System.Collections.Generic.List`1<System.Object>::get_Count() ldc.i4.0 <null> ceq <null> stloc.s V_16 ldloc.s V_16 brfalse.s IL_0193: ldc.i4.s 14 ldc.i4.8 <null> stloc.s V_24 br IL_0018: ldloc.s V_24 ldc.i4.s 14 br.s IL_018C: stloc.s V_24 leave IL_03D4: ret nop <null> br.s IL_019F: br.s IL_01A1 br.s IL_01A1: ldc.i4.3 ldc.i4.3 <null> stloc.s V_26 ldloc.s V_26 switch dnlib.DotNet.Emit.Instruction[] br.s IL_01DD: ldloc.s V_9 ldloc.s V_9 ldc.i4.0 <null> callvirt System.Object System.Collections.Generic.List`1<System.Object>::get_Item(System.Int32) ldnull <null> nop <null> ldc.i8 14 ldtoken 9NsoGrt1.pXs8H/qYe29zRmnL.3tzLeWb8e5Yf/L_y42EybFf.dTz38aeXgC1gsm call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) ldc.i4 2085448187 ldc.i4.4 <null> call System.String Bp3z2.tx5ZTbb92LqgWi/5MasRa0d.Wrk2nQ5k3tmGbe/oy2F3xMqA0incD.2LqprgG6S0::5tgTkYy0N6(System.Int64,System.Type,System.Int32,System.Int32) ldc.i4.0 <null> newarr System.Object ldnull <null> ldnull <null> ldnull <null> call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) castclass System.Collections.IEnumerable callvirt System.Collections.IEnumerator System.Collections.IEnumerable::GetEnumerator() stloc.s V_17 ldc.i4.2 <null> stloc.s V_26 br IL_01A4: ldloc.s V_26 ldloc.s V_17 callvirt System.Object System.Collections.IEnumerator::get_Current() call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.s V_18 ldloc.s V_18 brtrue.s IL_0242: ldc.i4.4 ldc.i4.s 11 stloc.s V_26 br IL_01A4: ldloc.s V_26 ldc.i4.4 <null> br.s IL_023B: stloc.s V_26 ldnull <null> br.s IL_027C: ldc.i4.1 ldloc.s V_18 ldnull <null> nop <null> ldc.i4 1920045877 ldc.i4.8 <null> ldnull <null> call System.String 5Tsyc1QfMa2.A_j6bm0TnG::2cgWR3nxaZ(System.Int32,System.Int32,System.String) ldc.i4.1 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldloc.2 <null> nop <null> ldc.i4.4 <null> ldc.i4 1661955196 ldnull <null> call System.String 5Tsyc1QfMa2.A_j6bm0TnG::kq3X1JorHfd85o(System.Int32,System.Int32,5Tsyc1QfMa2.A_j6bm0TnG) call System.String System.String::Concat(System.String,System.String) stelem.ref <null> ldnull <null> ldnull <null> ldnull <null> call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) ldc.i4.1 <null> box System.Boolean ldc.i4.0 <null> call System.Boolean Microsoft.VisualBasic.CompilerServices.Operators::ConditionalCompareObjectEqual(System.Object,System.Object,System.Boolean) stloc.s V_19 ldloc.s V_19 brfalse.s IL_0296: ldc.i4.0 ldc.i4.8 <null> stloc.s V_26 br IL_01A4: ldloc.s V_26 ldc.i4.0 <null> br.s IL_028F: stloc.s V_26 ldloc.s V_9 ldloc.s V_18 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) callvirt System.Void System.Collections.Generic.List`1<System.Object>::Add(System.Object) nop <null> ldc.i4.5 <null> stloc.s V_26 br IL_01A4: ldloc.s V_26 nop <null> nop <null> ldc.i4.2 <null> stloc.s V_26 br IL_01A4: ldloc.s V_26 ldloc.s V_17 callvirt System.Boolean System.Collections.IEnumerator::MoveNext() stloc.s V_20 ldloc.s V_20 brtrue.s IL_02CF: ldc.i4.s 9 ldc.i4.5 <null> stloc.s V_26 br IL_01A4: ldloc.s V_26 ldc.i4.s 9 br.s IL_02C8: stloc.s V_26 leave.s IL_0323: br.s IL_0325 br.s IL_02D7: ldc.i4.3 ldc.i4.3 <null> stloc.s V_28 ldloc.s V_28 switch dnlib.DotNet.Emit.Instruction[] br.s IL_02FF: ldloc.s V_17 ldloc.s V_17 isinst System.IDisposable brfalse.s IL_030D: ldc.i4.5 ldc.i4.6 <null> stloc.s V_28 br.s IL_02DA: ldloc.s V_28 ldc.i4.5 <null> br.s IL_0309: stloc.s V_28 ldloc.s V_17 isinst System.IDisposable callvirt System.Void System.IDisposable::Dispose() nop <null> ldc.i4.5 <null> stloc.s V_28 br.s IL_02DA: ldloc.s V_28 endfinally <null> br.s IL_0325: ldc.i4.4 ldc.i4.4 <null> stloc.s V_30 ldloc.s V_30 switch dnlib.DotNet.Emit.Instruction[] br.s IL_0351: ldc.r8 1 ldc.r8 1 stloc.s V_12 ldc.i4.1 <null> stloc.s V_21 ldc.i4.1 <null> stloc.s V_30 br.s IL_0328: ldloc.s V_30 ldloc.s V_12 ldloc.s V_21 ldc.i4.1 <null> add.ovf <null> conv.r8 <null> div <null> stloc.s V_12 ldloc.s V_21 ldc.i4.1 <null> add.ovf <null> stloc.s V_21 ldc.i4.6 <null> stloc.s V_30 br.s IL_0328: ldloc.s V_30 ldloc.s V_21 ldc.i4 10000 ble.s IL_0387: ldc.i4.1 ldc.i4.7 <null> stloc.s V_30 br.s IL_0328: ldloc.s V_30 ldc.i4.1 <null> br.s IL_0383: stloc.s V_30 ldloc.s V_9 call System.Void kGc6Ar2y.7zdRNm6ca8/tj9LiZ.9Tddwj0W3cCeyF::2knGJ(System.Collections.Generic.List`1<System.Object>) nop <null> leave.s IL_03A8: br.s IL_03AA br.s IL_0396: br.s IL_0398 br.s IL_0398: dup dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_22 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_03A8: br.s IL_03AA br.s IL_03AA: ldc.i4.0 ldc.i4.0 <null> stloc.s V_32 ldloc.s V_32 switch dnlib.DotNet.Emit.Instruction[] br.s IL_03CE: nop nop <null> ldc.i4.2 <null> stloc.s V_32 br.s IL_03AD: ldloc.s V_32 ret <null> ldtoken System.Void 9NsoGrt1.pXs8H/qYe29zRmnL.3tzLeWb8e5Yf::wc9To2W() pop <null> ret <null>

Module Name

zNq9aq1H

Full Name

zNq9aq1H

EntryPoint

System.Void 9NsoGrt1.pXs8H/qYe29zRmnL.3tzLeWb8e5Yf::wc9To2W()

Scope Name

zNq9aq1H

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

zNq9aq1H

Assembly Version

7.19.27.279

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

0

Main Method

System.Void 9NsoGrt1.pXs8H/qYe29zRmnL.3tzLeWb8e5Yf::wc9To2W()

Main IL Instruction Count

322

Main IL

nop <null> ldc.r8 1 stloc.0 <null> ldloca.s V_1 initobj System.Int16 br.s IL_0015: ldc.i4.6 ldc.i4.6 <null> stloc.s V_24 ldloc.s V_24 switch dnlib.DotNet.Emit.Instruction[] br.s IL_005D: nop nop <null> nop <null> ldc.i4 1920045871 ldc.i4.6 <null> ldnull <null> call System.String 5Tsyc1QfMa2.A_j6bm0TnG::2cgWR3nxaZ(System.Int32,System.Int32,System.String) stloc.2 <null> ldloc.2 <null> stloc.3 <null> ldc.i4.1 <null> stloc.s V_13 ldc.i4.1 <null> stloc.s V_24 br.s IL_0018: ldloc.s V_24 ldloc.3 <null> call System.Collections.Generic.IEnumerable`1<System.Char> System.Linq.Enumerable::Reverse<System.Char>(System.Collections.Generic.IEnumerable`1<System.Char>) call System.Char[] System.Linq.Enumerable::ToArray<System.Char>(System.Collections.Generic.IEnumerable`1<System.Char>) newobj System.Void System.String::.ctor(System.Char[]) stloc.3 <null> ldloc.s V_13 ldc.i4.1 <null> add.ovf <null> stloc.s V_13 ldloc.s V_13 ldc.i4 10000 ble.s IL_009E: ldc.i4.1 ldc.i4.3 <null> stloc.s V_24 br IL_0018: ldloc.s V_24 ldc.i4.1 <null> br.s IL_0097: stloc.s V_24 ldloc.2 <null> ldloca.s V_4 call System.Boolean System.DateTime::TryParse(System.String,System.DateTime&) pop <null> ldtoken System.Int32 call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) callvirt System.Reflection.Assembly System.Type::get_Assembly() stloc.s V_5 ldloc.s V_5 nop <null> ldc.i8 3 ldtoken 9NsoGrt1.pXs8H/qTs7io0SPqi1c6.3Byxo5Jz9Hmgik call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) ldc.i4 2085448065 ldc.i4.2 <null> call System.String Bp3z2.tx5ZTbb92LqgWi/5MasRa0d.Wrk2nQ5k3tmGbe/oy2F3xMqA0incD.2LqprgG6S0::5tgTkYy0N6(System.Int64,System.Type,System.Int32,System.Int32) callvirt System.Type System.Reflection.Assembly::GetType(System.String) stloc.s V_6 ldc.i4.s 11 stloc.s V_24 br IL_0018: ldloc.s V_24 ldtoken System.Object call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) stloc.s V_7 ldloc.s V_6 ldc.i4.1 <null> newarr System.Type dup <null> ldc.i4.0 <null> ldloc.s V_7 stelem.ref <null> callvirt System.Type System.Type::MakeGenericType(System.Type[]) stloc.s V_8 ldc.i4.0 <null> stloc.s V_24 br IL_0018: ldloc.s V_24 ldloc.s V_8 call System.Object System.Activator::CreateInstance(System.Type) castclass System.Collections.Generic.List`1<System.Object> stloc.s V_9 ldloc.s V_9 call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() callvirt System.Void System.Collections.Generic.List`1<System.Object>::Add(System.Object) nop <null> ldc.i4.0 <null> conv.i8 <null> stloc.s V_10 ldc.i4.2 <null> stloc.s V_24 br IL_0018: ldloc.s V_24 ldc.i4.1 <null> conv.i8 <null> stloc.s V_11 ldc.i4.1 <null> stloc.s V_14 ldc.i4.s 12 stloc.s V_24 br IL_0018: ldloc.s V_24 ldloc.s V_10 ldloc.s V_11 add.ovf <null> stloc.s V_15 ldloc.s V_11 stloc.s V_10 ldloc.s V_15 stloc.s V_11 ldloc.s V_14 ldc.i4.1 <null> add.ovf <null> stloc.s V_14 ldc.i4.4 <null> stloc.s V_24 br IL_0018: ldloc.s V_24 ldloc.s V_14 ldc.i4.s 50 ble.s IL_0177: ldc.i4.s 12 ldc.i4.s 10 stloc.s V_24 br IL_0018: ldloc.s V_24 ldc.i4.s 12 br.s IL_0170: stloc.s V_24 ldloc.s V_9 callvirt System.Int32 System.Collections.Generic.List`1<System.Object>::get_Count() ldc.i4.0 <null> ceq <null> stloc.s V_16 ldloc.s V_16 brfalse.s IL_0193: ldc.i4.s 14 ldc.i4.8 <null> stloc.s V_24 br IL_0018: ldloc.s V_24 ldc.i4.s 14 br.s IL_018C: stloc.s V_24 leave IL_03D4: ret nop <null> br.s IL_019F: br.s IL_01A1 br.s IL_01A1: ldc.i4.3 ldc.i4.3 <null> stloc.s V_26 ldloc.s V_26 switch dnlib.DotNet.Emit.Instruction[] br.s IL_01DD: ldloc.s V_9 ldloc.s V_9 ldc.i4.0 <null> callvirt System.Object System.Collections.Generic.List`1<System.Object>::get_Item(System.Int32) ldnull <null> nop <null> ldc.i8 14 ldtoken 9NsoGrt1.pXs8H/qYe29zRmnL.3tzLeWb8e5Yf/L_y42EybFf.dTz38aeXgC1gsm call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) ldc.i4 2085448187 ldc.i4.4 <null> call System.String Bp3z2.tx5ZTbb92LqgWi/5MasRa0d.Wrk2nQ5k3tmGbe/oy2F3xMqA0incD.2LqprgG6S0::5tgTkYy0N6(System.Int64,System.Type,System.Int32,System.Int32) ldc.i4.0 <null> newarr System.Object ldnull <null> ldnull <null> ldnull <null> call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) castclass System.Collections.IEnumerable callvirt System.Collections.IEnumerator System.Collections.IEnumerable::GetEnumerator() stloc.s V_17 ldc.i4.2 <null> stloc.s V_26 br IL_01A4: ldloc.s V_26 ldloc.s V_17 callvirt System.Object System.Collections.IEnumerator::get_Current() call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.s V_18 ldloc.s V_18 brtrue.s IL_0242: ldc.i4.4 ldc.i4.s 11 stloc.s V_26 br IL_01A4: ldloc.s V_26 ldc.i4.4 <null> br.s IL_023B: stloc.s V_26 ldnull <null> br.s IL_027C: ldc.i4.1 ldloc.s V_18 ldnull <null> nop <null> ldc.i4 1920045877 ldc.i4.8 <null> ldnull <null> call System.String 5Tsyc1QfMa2.A_j6bm0TnG::2cgWR3nxaZ(System.Int32,System.Int32,System.String) ldc.i4.1 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldloc.2 <null> nop <null> ldc.i4.4 <null> ldc.i4 1661955196 ldnull <null> call System.String 5Tsyc1QfMa2.A_j6bm0TnG::kq3X1JorHfd85o(System.Int32,System.Int32,5Tsyc1QfMa2.A_j6bm0TnG) call System.String System.String::Concat(System.String,System.String) stelem.ref <null> ldnull <null> ldnull <null> ldnull <null> call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) ldc.i4.1 <null> box System.Boolean ldc.i4.0 <null> call System.Boolean Microsoft.VisualBasic.CompilerServices.Operators::ConditionalCompareObjectEqual(System.Object,System.Object,System.Boolean) stloc.s V_19 ldloc.s V_19 brfalse.s IL_0296: ldc.i4.0 ldc.i4.8 <null> stloc.s V_26 br IL_01A4: ldloc.s V_26 ldc.i4.0 <null> br.s IL_028F: stloc.s V_26 ldloc.s V_9 ldloc.s V_18 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) callvirt System.Void System.Collections.Generic.List`1<System.Object>::Add(System.Object) nop <null> ldc.i4.5 <null> stloc.s V_26 br IL_01A4: ldloc.s V_26 nop <null> nop <null> ldc.i4.2 <null> stloc.s V_26 br IL_01A4: ldloc.s V_26 ldloc.s V_17 callvirt System.Boolean System.Collections.IEnumerator::MoveNext() stloc.s V_20 ldloc.s V_20 brtrue.s IL_02CF: ldc.i4.s 9 ldc.i4.5 <null> stloc.s V_26 br IL_01A4: ldloc.s V_26 ldc.i4.s 9 br.s IL_02C8: stloc.s V_26 leave.s IL_0323: br.s IL_0325 br.s IL_02D7: ldc.i4.3 ldc.i4.3 <null> stloc.s V_28 ldloc.s V_28 switch dnlib.DotNet.Emit.Instruction[] br.s IL_02FF: ldloc.s V_17 ldloc.s V_17 isinst System.IDisposable brfalse.s IL_030D: ldc.i4.5 ldc.i4.6 <null> stloc.s V_28 br.s IL_02DA: ldloc.s V_28 ldc.i4.5 <null> br.s IL_0309: stloc.s V_28 ldloc.s V_17 isinst System.IDisposable callvirt System.Void System.IDisposable::Dispose() nop <null> ldc.i4.5 <null> stloc.s V_28 br.s IL_02DA: ldloc.s V_28 endfinally <null> br.s IL_0325: ldc.i4.4 ldc.i4.4 <null> stloc.s V_30 ldloc.s V_30 switch dnlib.DotNet.Emit.Instruction[] br.s IL_0351: ldc.r8 1 ldc.r8 1 stloc.s V_12 ldc.i4.1 <null> stloc.s V_21 ldc.i4.1 <null> stloc.s V_30 br.s IL_0328: ldloc.s V_30 ldloc.s V_12 ldloc.s V_21 ldc.i4.1 <null> add.ovf <null> conv.r8 <null> div <null> stloc.s V_12 ldloc.s V_21 ldc.i4.1 <null> add.ovf <null> stloc.s V_21 ldc.i4.6 <null> stloc.s V_30 br.s IL_0328: ldloc.s V_30 ldloc.s V_21 ldc.i4 10000 ble.s IL_0387: ldc.i4.1 ldc.i4.7 <null> stloc.s V_30 br.s IL_0328: ldloc.s V_30 ldc.i4.1 <null> br.s IL_0383: stloc.s V_30 ldloc.s V_9 call System.Void kGc6Ar2y.7zdRNm6ca8/tj9LiZ.9Tddwj0W3cCeyF::2knGJ(System.Collections.Generic.List`1<System.Object>) nop <null> leave.s IL_03A8: br.s IL_03AA br.s IL_0396: br.s IL_0398 br.s IL_0398: dup dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_22 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_03A8: br.s IL_03AA br.s IL_03AA: ldc.i4.0 ldc.i4.0 <null> stloc.s V_32 ldloc.s V_32 switch dnlib.DotNet.Emit.Instruction[] br.s IL_03CE: nop nop <null> ldc.i4.2 <null> stloc.s V_32 br.s IL_03AD: ldloc.s V_32 ret <null> ldtoken System.Void 9NsoGrt1.pXs8H/qYe29zRmnL.3tzLeWb8e5Yf::wc9To2W() pop <null> ret <null>

ff617fc5d1968e2d95a7aec28cefac4a (701.44 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Kezada.jeydaseba.bat
zNq9aq1H.Resources.resources
2928bc919ed12d.Resources.resources
228fa9c30
[NBF]root.Data
228fa9c31
[NBF]root.Data
228fa9c32
[NBF]root.Data
228fa9c33
[NBF]root.Data
228fa9c34
[NBF]root.Data
228fa9c35
[NBF]root.Data
228fa9c36
[NBF]root.Data
228fa9c37
[NBF]root.Data
228fa9c38
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙