finddotnet.disasm 25 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438
  1. Microsoft (R) COFF/PE Dumper Version 14.29.30148.0
  2. Copyright (C) Microsoft Corporation. All rights reserved.
  3. Dump of file finddotnet.o
  4. File Type: COFF OBJECT
  5. BeaconPrintToStreamW:
  6. 0000000000000000: 48 89 4C 24 08 mov qword ptr [rsp+8],rcx
  7. 0000000000000005: 48 89 54 24 10 mov qword ptr [rsp+10h],rdx
  8. 000000000000000A: 4C 89 44 24 18 mov qword ptr [rsp+18h],r8
  9. 000000000000000F: 4C 89 4C 24 20 mov qword ptr [rsp+20h],r9
  10. 0000000000000014: 48 83 EC 58 sub rsp,58h
  11. 0000000000000018: C7 44 24 30 01 00 mov dword ptr [rsp+30h],1
  12. 00 00
  13. 0000000000000020: C7 44 24 34 00 00 mov dword ptr [rsp+34h],0
  14. 00 00
  15. 0000000000000028: 48 83 3D 00 00 00 cmp qword ptr [g_lpStream],1
  16. 00 01
  17. 0000000000000030: 77 28 ja 000000000000005A
  18. 0000000000000032: 4C 8D 05 00 00 00 lea r8,[g_lpStream]
  19. 00
  20. 0000000000000039: BA 01 00 00 00 mov edx,1
  21. 000000000000003E: 33 C9 xor ecx,ecx
  22. 0000000000000040: FF 15 00 00 00 00 call qword ptr [__imp_OLE32$CreateStreamOnHGlobal]
  23. 0000000000000046: 89 44 24 30 mov dword ptr [rsp+30h],eax
  24. 000000000000004A: 83 7C 24 30 00 cmp dword ptr [rsp+30h],0
  25. 000000000000004F: 7D 09 jge 000000000000005A
  26. 0000000000000051: 8B 44 24 30 mov eax,dword ptr [rsp+30h]
  27. 0000000000000055: E9 01 01 00 00 jmp 000000000000015B
  28. 000000000000005A: 48 83 3D 00 00 00 cmp qword ptr [g_lpwPrintBuffer],1
  29. 00 01
  30. 0000000000000062: 77 2E ja 0000000000000092
  31. 0000000000000064: BA 02 00 00 00 mov edx,2
  32. 0000000000000069: B9 00 20 00 00 mov ecx,2000h
  33. 000000000000006E: FF 15 00 00 00 00 call qword ptr [__imp_MSVCRT$calloc]
  34. 0000000000000074: 48 89 05 00 00 00 mov qword ptr [g_lpwPrintBuffer],rax
  35. 00
  36. 000000000000007B: 48 83 3D 00 00 00 cmp qword ptr [g_lpwPrintBuffer],0
  37. 00 00
  38. 0000000000000083: 75 0D jne 0000000000000092
  39. 0000000000000085: C7 44 24 30 05 40 mov dword ptr [rsp+30h],80004005h
  40. 00 80
  41. 000000000000008D: E9 9D 00 00 00 jmp 000000000000012F
  42. 0000000000000092: 48 8D 44 24 68 lea rax,[rsp+68h]
  43. 0000000000000097: 48 89 44 24 38 mov qword ptr [rsp+38h],rax
  44. 000000000000009C: 48 8B 44 24 38 mov rax,qword ptr [rsp+38h]
  45. 00000000000000A1: 48 89 44 24 20 mov qword ptr [rsp+20h],rax
  46. 00000000000000A6: 4C 8B 4C 24 60 mov r9,qword ptr [rsp+60h]
  47. 00000000000000AB: 41 B8 FF 1F 00 00 mov r8d,1FFFh
  48. 00000000000000B1: BA 00 20 00 00 mov edx,2000h
  49. 00000000000000B6: 48 8B 0D 00 00 00 mov rcx,qword ptr [g_lpwPrintBuffer]
  50. 00
  51. 00000000000000BD: FF 15 00 00 00 00 call qword ptr [__imp_MSVCRT$_vsnwprintf_s]
  52. 00000000000000C3: 85 C0 test eax,eax
  53. 00000000000000C5: 75 0A jne 00000000000000D1
  54. 00000000000000C7: C7 44 24 30 05 40 mov dword ptr [rsp+30h],80004005h
  55. 00 80
  56. 00000000000000CF: EB 5E jmp 000000000000012F
  57. 00000000000000D1: 48 83 3D 00 00 00 cmp qword ptr [g_lpStream],0
  58. 00 00
  59. 00000000000000D9: 74 4C je 0000000000000127
  60. 00000000000000DB: 48 8B 0D 00 00 00 mov rcx,qword ptr [g_lpwPrintBuffer]
  61. 00
  62. 00000000000000E2: FF 15 00 00 00 00 call qword ptr [__imp_MSVCRT$wcslen]
  63. 00000000000000E8: 8B C0 mov eax,eax
  64. 00000000000000EA: 48 D1 E0 shl rax,1
  65. 00000000000000ED: 48 8B 0D 00 00 00 mov rcx,qword ptr [g_lpStream]
  66. 00
  67. 00000000000000F4: 48 8B 09 mov rcx,qword ptr [rcx]
  68. 00000000000000F7: 48 89 4C 24 40 mov qword ptr [rsp+40h],rcx
  69. 00000000000000FC: 4C 8D 4C 24 34 lea r9,[rsp+34h]
  70. 0000000000000101: 44 8B C0 mov r8d,eax
  71. 0000000000000104: 48 8B 15 00 00 00 mov rdx,qword ptr [g_lpwPrintBuffer]
  72. 00
  73. 000000000000010B: 48 8B 0D 00 00 00 mov rcx,qword ptr [g_lpStream]
  74. 00
  75. 0000000000000112: 48 8B 44 24 40 mov rax,qword ptr [rsp+40h]
  76. 0000000000000117: FF 50 20 call qword ptr [rax+20h]
  77. 000000000000011A: 89 44 24 30 mov dword ptr [rsp+30h],eax
  78. 000000000000011E: 83 7C 24 30 00 cmp dword ptr [rsp+30h],0
  79. 0000000000000123: 7D 02 jge 0000000000000127
  80. 0000000000000125: EB 08 jmp 000000000000012F
  81. 0000000000000127: C7 44 24 30 00 00 mov dword ptr [rsp+30h],0
  82. 00 00
  83. 000000000000012F: 48 83 3D 00 00 00 cmp qword ptr [g_lpwPrintBuffer],0
  84. 00 00
  85. 0000000000000137: 74 15 je 000000000000014E
  86. 0000000000000139: 41 B8 00 40 00 00 mov r8d,4000h
  87. 000000000000013F: 33 D2 xor edx,edx
  88. 0000000000000141: 48 8B 0D 00 00 00 mov rcx,qword ptr [g_lpwPrintBuffer]
  89. 00
  90. 0000000000000148: FF 15 00 00 00 00 call qword ptr [__imp_MSVCRT$memset]
  91. 000000000000014E: 48 C7 44 24 38 00 mov qword ptr [rsp+38h],0
  92. 00 00 00
  93. 0000000000000157: 8B 44 24 30 mov eax,dword ptr [rsp+30h]
  94. 000000000000015B: 48 83 C4 58 add rsp,58h
  95. 000000000000015F: C3 ret
  96. 0000000000000160: CC int 3
  97. 0000000000000161: CC int 3
  98. 0000000000000162: CC int 3
  99. 0000000000000163: CC int 3
  100. 0000000000000164: CC int 3
  101. 0000000000000165: CC int 3
  102. 0000000000000166: CC int 3
  103. 0000000000000167: CC int 3
  104. 0000000000000168: CC int 3
  105. 0000000000000169: CC int 3
  106. 000000000000016A: CC int 3
  107. 000000000000016B: CC int 3
  108. 000000000000016C: CC int 3
  109. 000000000000016D: CC int 3
  110. 000000000000016E: CC int 3
  111. 000000000000016F: CC int 3
  112. BeaconOutputStreamW:
  113. 0000000000000170: 40 57 push rdi
  114. 0000000000000172: 48 81 EC A0 00 00 sub rsp,0A0h
  115. 00
  116. 0000000000000179: 48 8D 44 24 50 lea rax,[rsp+50h]
  117. 000000000000017E: 48 8B F8 mov rdi,rax
  118. 0000000000000181: 33 C0 xor eax,eax
  119. 0000000000000183: B9 50 00 00 00 mov ecx,50h
  120. 0000000000000188: F3 AA rep stos byte ptr [rdi]
  121. 000000000000018A: 48 C7 44 24 30 00 mov qword ptr [rsp+30h],0
  122. 00 00 00
  123. 0000000000000193: C7 44 24 28 00 00 mov dword ptr [rsp+28h],0
  124. 00 00
  125. 000000000000019B: 48 C7 44 24 20 00 mov qword ptr [rsp+20h],0
  126. 00 00 00
  127. 00000000000001A4: 48 8B 05 00 00 00 mov rax,qword ptr [g_lpStream]
  128. 00
  129. 00000000000001AB: 48 8B 00 mov rax,qword ptr [rax]
  130. 00000000000001AE: 41 B8 01 00 00 00 mov r8d,1
  131. 00000000000001B4: 48 8D 54 24 50 lea rdx,[rsp+50h]
  132. 00000000000001B9: 48 8B 0D 00 00 00 mov rcx,qword ptr [g_lpStream]
  133. 00
  134. 00000000000001C0: FF 50 60 call qword ptr [rax+60h]
  135. 00000000000001C3: 85 C0 test eax,eax
  136. 00000000000001C5: 7D 05 jge 00000000000001CC
  137. 00000000000001C7: E9 13 01 00 00 jmp 00000000000002DF
  138. 00000000000001CC: 8B 44 24 60 mov eax,dword ptr [rsp+60h]
  139. 00000000000001D0: 48 89 44 24 30 mov qword ptr [rsp+30h],rax
  140. 00000000000001D5: 48 8B 44 24 30 mov rax,qword ptr [rsp+30h]
  141. 00000000000001DA: 48 FF C0 inc rax
  142. 00000000000001DD: 48 89 44 24 38 mov qword ptr [rsp+38h],rax
  143. 00000000000001E2: FF 15 00 00 00 00 call qword ptr [__imp_KERNEL32$GetProcessHeap]
  144. 00000000000001E8: 48 8B 4C 24 38 mov rcx,qword ptr [rsp+38h]
  145. 00000000000001ED: 4C 8B C1 mov r8,rcx
  146. 00000000000001F0: BA 08 00 00 00 mov edx,8
  147. 00000000000001F5: 48 8B C8 mov rcx,rax
  148. 00000000000001F8: FF 15 00 00 00 00 call qword ptr [__imp_KERNEL32$HeapAlloc]
  149. 00000000000001FE: 48 89 44 24 20 mov qword ptr [rsp+20h],rax
  150. 0000000000000203: 48 83 7C 24 20 00 cmp qword ptr [rsp+20h],0
  151. 0000000000000209: 74 6B je 0000000000000276
  152. 000000000000020B: 48 C7 44 24 40 00 mov qword ptr [rsp+40h],0
  153. 00 00 00
  154. 0000000000000214: 48 8B 05 00 00 00 mov rax,qword ptr [g_lpStream]
  155. 00
  156. 000000000000021B: 48 8B 00 mov rax,qword ptr [rax]
  157. 000000000000021E: 45 33 C9 xor r9d,r9d
  158. 0000000000000221: 45 33 C0 xor r8d,r8d
  159. 0000000000000224: 48 8B 54 24 40 mov rdx,qword ptr [rsp+40h]
  160. 0000000000000229: 48 8B 0D 00 00 00 mov rcx,qword ptr [g_lpStream]
  161. 00
  162. 0000000000000230: FF 50 28 call qword ptr [rax+28h]
  163. 0000000000000233: 85 C0 test eax,eax
  164. 0000000000000235: 7D 02 jge 0000000000000239
  165. 0000000000000237: EB 3D jmp 0000000000000276
  166. 0000000000000239: 48 8B 05 00 00 00 mov rax,qword ptr [g_lpStream]
  167. 00
  168. 0000000000000240: 48 8B 00 mov rax,qword ptr [rax]
  169. 0000000000000243: 4C 8D 4C 24 28 lea r9,[rsp+28h]
  170. 0000000000000248: 44 8B 44 24 30 mov r8d,dword ptr [rsp+30h]
  171. 000000000000024D: 48 8B 54 24 20 mov rdx,qword ptr [rsp+20h]
  172. 0000000000000252: 48 8B 0D 00 00 00 mov rcx,qword ptr [g_lpStream]
  173. 00
  174. 0000000000000259: FF 50 18 call qword ptr [rax+18h]
  175. 000000000000025C: 85 C0 test eax,eax
  176. 000000000000025E: 7D 02 jge 0000000000000262
  177. 0000000000000260: EB 14 jmp 0000000000000276
  178. 0000000000000262: 4C 8B 44 24 20 mov r8,qword ptr [rsp+20h]
  179. 0000000000000267: 48 8D 15 00 00 00 lea rdx,[$SG105371]
  180. 00
  181. 000000000000026E: 33 C9 xor ecx,ecx
  182. 0000000000000270: FF 15 00 00 00 00 call qword ptr [__imp_BeaconPrintf]
  183. 0000000000000276: 48 83 3D 00 00 00 cmp qword ptr [g_lpStream],0
  184. 00 00
  185. 000000000000027E: 74 1F je 000000000000029F
  186. 0000000000000280: 48 8B 05 00 00 00 mov rax,qword ptr [g_lpStream]
  187. 00
  188. 0000000000000287: 48 8B 00 mov rax,qword ptr [rax]
  189. 000000000000028A: 48 8B 0D 00 00 00 mov rcx,qword ptr [g_lpStream]
  190. 00
  191. 0000000000000291: FF 50 10 call qword ptr [rax+10h]
  192. 0000000000000294: 48 C7 05 00 00 00 mov qword ptr [g_lpStream],0
  193. 00 00 00 00 00
  194. 000000000000029F: 48 83 3D 00 00 00 cmp qword ptr [g_lpwPrintBuffer],0
  195. 00 00
  196. 00000000000002A7: 74 18 je 00000000000002C1
  197. 00000000000002A9: 48 8B 0D 00 00 00 mov rcx,qword ptr [g_lpwPrintBuffer]
  198. 00
  199. 00000000000002B0: FF 15 00 00 00 00 call qword ptr [__imp_MSVCRT$free]
  200. 00000000000002B6: 48 C7 05 00 00 00 mov qword ptr [g_lpwPrintBuffer],0
  201. 00 00 00 00 00
  202. 00000000000002C1: 48 83 7C 24 20 00 cmp qword ptr [rsp+20h],0
  203. 00000000000002C7: 74 16 je 00000000000002DF
  204. 00000000000002C9: FF 15 00 00 00 00 call qword ptr [__imp_KERNEL32$GetProcessHeap]
  205. 00000000000002CF: 4C 8B 44 24 20 mov r8,qword ptr [rsp+20h]
  206. 00000000000002D4: 33 D2 xor edx,edx
  207. 00000000000002D6: 48 8B C8 mov rcx,rax
  208. 00000000000002D9: FF 15 00 00 00 00 call qword ptr [__imp_KERNEL32$HeapFree]
  209. 00000000000002DF: 48 81 C4 A0 00 00 add rsp,0A0h
  210. 00
  211. 00000000000002E6: 5F pop rdi
  212. 00000000000002E7: C3 ret
  213. 00000000000002E8: CC int 3
  214. 00000000000002E9: CC int 3
  215. 00000000000002EA: CC int 3
  216. 00000000000002EB: CC int 3
  217. 00000000000002EC: CC int 3
  218. 00000000000002ED: CC int 3
  219. 00000000000002EE: CC int 3
  220. 00000000000002EF: CC int 3
  221. FindDotNet:
  222. 00000000000002F0: 40 56 push rsi
  223. 00000000000002F2: 57 push rdi
  224. 00000000000002F3: 48 81 EC 68 04 00 sub rsp,468h
  225. 00
  226. 00000000000002FA: C7 44 24 70 00 00 mov dword ptr [rsp+70h],0
  227. 00 00
  228. 0000000000000302: C7 44 24 30 00 00 mov dword ptr [rsp+30h],0
  229. 00 00
  230. 000000000000030A: 48 C7 44 24 38 00 mov qword ptr [rsp+38h],0
  231. 00 00 00
  232. 0000000000000313: 48 8D 44 24 40 lea rax,[rsp+40h]
  233. 0000000000000318: 48 8B F8 mov rdi,rax
  234. 000000000000031B: 33 C0 xor eax,eax
  235. 000000000000031D: B9 10 00 00 00 mov ecx,10h
  236. 0000000000000322: F3 AA rep stos byte ptr [rdi]
  237. 0000000000000324: C7 44 24 34 00 00 mov dword ptr [rsp+34h],0
  238. 00 00
  239. 000000000000032C: 48 8D 0D 00 00 00 lea rcx,[$SG105407]
  240. 00
  241. 0000000000000333: FF 15 00 00 00 00 call qword ptr [__imp_GetModuleHandleA]
  242. 0000000000000339: 48 8D 15 00 00 00 lea rdx,[$SG105406]
  243. 00
  244. 0000000000000340: 48 8B C8 mov rcx,rax
  245. 0000000000000343: FF 15 00 00 00 00 call qword ptr [__imp_GetProcAddress]
  246. 0000000000000349: 48 89 44 24 58 mov qword ptr [rsp+58h],rax
  247. 000000000000034E: 48 8D 0D 00 00 00 lea rcx,[$SG105409]
  248. 00
  249. 0000000000000355: FF 15 00 00 00 00 call qword ptr [__imp_GetModuleHandleA]
  250. 000000000000035B: 48 8D 15 00 00 00 lea rdx,[$SG105408]
  251. 00
  252. 0000000000000362: 48 8B C8 mov rcx,rax
  253. 0000000000000365: FF 15 00 00 00 00 call qword ptr [__imp_GetProcAddress]
  254. 000000000000036B: 48 89 44 24 60 mov qword ptr [rsp+60h],rax
  255. 0000000000000370: 48 83 7C 24 58 00 cmp qword ptr [rsp+58h],0
  256. 0000000000000376: 74 08 je 0000000000000380
  257. 0000000000000378: 48 83 7C 24 60 00 cmp qword ptr [rsp+60h],0
  258. 000000000000037E: 75 1C jne 000000000000039C
  259. 0000000000000380: 48 8D 15 00 00 00 lea rdx,[$SG105412]
  260. 00
  261. 0000000000000387: B9 0D 00 00 00 mov ecx,0Dh
  262. 000000000000038C: FF 15 00 00 00 00 call qword ptr [__imp_BeaconPrintf]
  263. 0000000000000392: B8 FF FF FF FF mov eax,0FFFFFFFFh
  264. 0000000000000397: E9 17 02 00 00 jmp 00000000000005B3
  265. 000000000000039C: 48 8D 84 24 B0 00 lea rax,[rsp+0B0h]
  266. 00 00
  267. 00000000000003A4: 48 8D 0D 00 00 00 lea rcx,[$SG105413]
  268. 00
  269. 00000000000003AB: 48 8B F8 mov rdi,rax
  270. 00000000000003AE: 48 8B F1 mov rsi,rcx
  271. 00000000000003B1: B9 56 00 00 00 mov ecx,56h
  272. 00000000000003B6: F3 A4 rep movs byte ptr [rdi],byte ptr [rsi]
  273. 00000000000003B8: FF 15 00 00 00 00 call qword ptr [__imp_KERNEL32$GetProcessHeap]
  274. 00000000000003BE: 41 B8 F4 01 00 00 mov r8d,1F4h
  275. 00000000000003C4: BA 08 00 00 00 mov edx,8
  276. 00000000000003C9: 48 8B C8 mov rcx,rax
  277. 00000000000003CC: FF 15 00 00 00 00 call qword ptr [__imp_KERNEL32$HeapAlloc]
  278. 00000000000003D2: 48 89 44 24 48 mov qword ptr [rsp+48h],rax
  279. 00000000000003D7: 48 8D 0D 00 00 00 lea rcx,[$SG105414]
  280. 00
  281. 00000000000003DE: E8 00 00 00 00 call BeaconPrintToStreamW
  282. 00000000000003E3: 48 8D 0D 00 00 00 lea rcx,[$SG105415]
  283. 00
  284. 00000000000003EA: E8 00 00 00 00 call BeaconPrintToStreamW
  285. 00000000000003EF: 48 8D 44 24 38 lea rax,[rsp+38h]
  286. 00000000000003F4: 48 89 44 24 20 mov qword ptr [rsp+20h],rax
  287. 00000000000003F9: 45 33 C9 xor r9d,r9d
  288. 00000000000003FC: 45 33 C0 xor r8d,r8d
  289. 00000000000003FF: BA 00 00 00 02 mov edx,2000000h
  290. 0000000000000404: 48 8B 4C 24 38 mov rcx,qword ptr [rsp+38h]
  291. 0000000000000409: FF 54 24 58 call qword ptr [rsp+58h]
  292. 000000000000040D: 85 C0 test eax,eax
  293. 000000000000040F: 0F 85 9A 01 00 00 jne 00000000000005AF
  294. 0000000000000415: 48 8B 4C 24 38 mov rcx,qword ptr [rsp+38h]
  295. 000000000000041A: FF 15 00 00 00 00 call qword ptr [__imp_KERNEL32$GetProcessId]
  296. 0000000000000420: 89 44 24 30 mov dword ptr [rsp+30h],eax
  297. 0000000000000424: 83 7C 24 30 00 cmp dword ptr [rsp+30h],0
  298. 0000000000000429: 75 02 jne 000000000000042D
  299. 000000000000042B: EB C2 jmp 00000000000003EF
  300. 000000000000042D: 44 8B 44 24 30 mov r8d,dword ptr [rsp+30h]
  301. 0000000000000432: 48 8D 15 00 00 00 lea rdx,[$SG105417]
  302. 00
  303. 0000000000000439: 48 8D 8C 24 10 01 lea rcx,[rsp+110h]
  304. 00 00
  305. 0000000000000441: FF 15 00 00 00 00 call qword ptr [__imp_USER32$wsprintfW]
  306. 0000000000000447: 41 B8 F4 01 00 00 mov r8d,1F4h
  307. 000000000000044D: 33 D2 xor edx,edx
  308. 000000000000044F: 48 8B 4C 24 48 mov rcx,qword ptr [rsp+48h]
  309. 0000000000000454: FF 15 00 00 00 00 call qword ptr [__imp_MSVCRT$memset]
  310. 000000000000045A: 48 8D 8C 24 B0 00 lea rcx,[rsp+0B0h]
  311. 00 00
  312. 0000000000000462: FF 15 00 00 00 00 call qword ptr [__imp_MSVCRT$wcslen]
  313. 0000000000000468: 48 D1 E0 shl rax,1
  314. 000000000000046B: 4C 8B C0 mov r8,rax
  315. 000000000000046E: 48 8D 94 24 B0 00 lea rdx,[rsp+0B0h]
  316. 00 00
  317. 0000000000000476: 48 8B 4C 24 48 mov rcx,qword ptr [rsp+48h]
  318. 000000000000047B: FF 15 00 00 00 00 call qword ptr [__imp_MSVCRT$memcpy]
  319. 0000000000000481: 48 8D 94 24 10 01 lea rdx,[rsp+110h]
  320. 00 00
  321. 0000000000000489: 48 8B 4C 24 48 mov rcx,qword ptr [rsp+48h]
  322. 000000000000048E: FF 15 00 00 00 00 call qword ptr [__imp_KERNEL32$lstrcatW]
  323. 0000000000000494: 48 8B 4C 24 48 mov rcx,qword ptr [rsp+48h]
  324. 0000000000000499: FF 15 00 00 00 00 call qword ptr [__imp_MSVCRT$wcslen]
  325. 000000000000049F: 48 D1 E0 shl rax,1
  326. 00000000000004A2: 66 89 44 24 40 mov word ptr [rsp+40h],ax
  327. 00000000000004A7: 0F B7 44 24 40 movzx eax,word ptr [rsp+40h]
  328. 00000000000004AC: FF C0 inc eax
  329. 00000000000004AE: 66 89 44 24 42 mov word ptr [rsp+42h],ax
  330. 00000000000004B3: C7 84 24 80 00 00 mov dword ptr [rsp+80h],30h
  331. 00 30 00 00 00
  332. 00000000000004BE: 48 C7 84 24 88 00 mov qword ptr [rsp+88h],0
  333. 00 00 00 00 00 00
  334. 00000000000004CA: C7 84 24 98 00 00 mov dword ptr [rsp+98h],40h
  335. 00 40 00 00 00
  336. 00000000000004D5: 48 8D 44 24 40 lea rax,[rsp+40h]
  337. 00000000000004DA: 48 89 84 24 90 00 mov qword ptr [rsp+90h],rax
  338. 00 00
  339. 00000000000004E2: 48 C7 84 24 A0 00 mov qword ptr [rsp+0A0h],0
  340. 00 00 00 00 00 00
  341. 00000000000004EE: 48 C7 84 24 A8 00 mov qword ptr [rsp+0A8h],0
  342. 00 00 00 00 00 00
  343. 00000000000004FA: 48 C7 44 24 68 00 mov qword ptr [rsp+68h],0
  344. 00 00 00
  345. 0000000000000503: 4C 8D 84 24 80 00 lea r8,[rsp+80h]
  346. 00 00
  347. 000000000000050B: BA 01 00 00 00 mov edx,1
  348. 0000000000000510: 48 8D 4C 24 68 lea rcx,[rsp+68h]
  349. 0000000000000515: FF 54 24 60 call qword ptr [rsp+60h]
  350. 0000000000000519: 89 44 24 50 mov dword ptr [rsp+50h],eax
  351. 000000000000051D: 83 7C 24 50 00 cmp dword ptr [rsp+50h],0
  352. 0000000000000522: 0F 8C 82 00 00 00 jl 00000000000005AA
  353. 0000000000000528: 48 8B 4C 24 68 mov rcx,qword ptr [rsp+68h]
  354. 000000000000052D: FF 15 00 00 00 00 call qword ptr [__imp_KERNEL32$CloseHandle]
  355. 0000000000000533: 41 B8 04 01 00 00 mov r8d,104h
  356. 0000000000000539: 48 8D 94 24 50 01 lea rdx,[rsp+150h]
  357. 00 00
  358. 0000000000000541: 48 8B 4C 24 38 mov rcx,qword ptr [rsp+38h]
  359. 0000000000000546: FF 15 00 00 00 00 call qword ptr [__imp_KERNEL32$K32GetProcessImageFileNameA]
  360. 000000000000054C: 48 8D 8C 24 50 01 lea rcx,[rsp+150h]
  361. 00 00
  362. 0000000000000554: FF 15 00 00 00 00 call qword ptr [__imp_SHLWAPI$PathFindFileNameA]
  363. 000000000000055A: 48 89 44 24 78 mov qword ptr [rsp+78h],rax
  364. 000000000000055F: C7 44 24 28 00 01 mov dword ptr [rsp+28h],100h
  365. 00 00
  366. 0000000000000567: 48 8D 84 24 60 02 lea rax,[rsp+260h]
  367. 00 00
  368. 000000000000056F: 48 89 44 24 20 mov qword ptr [rsp+20h],rax
  369. 0000000000000574: 41 B9 FF FF FF FF mov r9d,0FFFFFFFFh
  370. 000000000000057A: 4C 8B 44 24 78 mov r8,qword ptr [rsp+78h]
  371. 000000000000057F: 33 D2 xor edx,edx
  372. 0000000000000581: 33 C9 xor ecx,ecx
  373. 0000000000000583: FF 15 00 00 00 00 call qword ptr [__imp_KERNEL32$MultiByteToWideChar]
  374. 0000000000000589: 44 8B 44 24 30 mov r8d,dword ptr [rsp+30h]
  375. 000000000000058E: 48 8D 94 24 60 02 lea rdx,[rsp+260h]
  376. 00 00
  377. 0000000000000596: 48 8D 0D 00 00 00 lea rcx,[$SG105419]
  378. 00
  379. 000000000000059D: E8 00 00 00 00 call BeaconPrintToStreamW
  380. 00000000000005A2: C7 44 24 34 01 00 mov dword ptr [rsp+34h],1
  381. 00 00
  382. 00000000000005AA: E9 40 FE FF FF jmp 00000000000003EF
  383. 00000000000005AF: 8B 44 24 34 mov eax,dword ptr [rsp+34h]
  384. 00000000000005B3: 48 81 C4 68 04 00 add rsp,468h
  385. 00
  386. 00000000000005BA: 5F pop rdi
  387. 00000000000005BB: 5E pop rsi
  388. 00000000000005BC: C3 ret
  389. 00000000000005BD: CC int 3
  390. 00000000000005BE: CC int 3
  391. 00000000000005BF: CC int 3
  392. 00000000000005C0: CC int 3
  393. 00000000000005C1: CC int 3
  394. 00000000000005C2: CC int 3
  395. 00000000000005C3: CC int 3
  396. 00000000000005C4: CC int 3
  397. 00000000000005C5: CC int 3
  398. 00000000000005C6: CC int 3
  399. 00000000000005C7: CC int 3
  400. 00000000000005C8: CC int 3
  401. 00000000000005C9: CC int 3
  402. 00000000000005CA: CC int 3
  403. 00000000000005CB: CC int 3
  404. 00000000000005CC: CC int 3
  405. 00000000000005CD: CC int 3
  406. 00000000000005CE: CC int 3
  407. 00000000000005CF: CC int 3
  408. go:
  409. 00000000000005D0: 48 83 EC 38 sub rsp,38h
  410. 00000000000005D4: C7 44 24 20 00 00 mov dword ptr [rsp+20h],0
  411. 00 00
  412. 00000000000005DC: E8 00 00 00 00 call FindDotNet
  413. 00000000000005E1: 89 44 24 20 mov dword ptr [rsp+20h],eax
  414. 00000000000005E5: 83 7C 24 20 00 cmp dword ptr [rsp+20h],0
  415. 00000000000005EA: 75 14 jne 0000000000000600
  416. 00000000000005EC: 48 8D 15 00 00 00 lea rdx,[$SG105427]
  417. 00
  418. 00000000000005F3: B9 0D 00 00 00 mov ecx,0Dh
  419. 00000000000005F8: FF 15 00 00 00 00 call qword ptr [__imp_BeaconPrintf]
  420. 00000000000005FE: EB 05 jmp 0000000000000605
  421. 0000000000000600: E8 00 00 00 00 call BeaconOutputStreamW
  422. 0000000000000605: 33 C0 xor eax,eax
  423. 0000000000000607: 48 83 C4 38 add rsp,38h
  424. 000000000000060B: C3 ret
  425. Summary
  426. 38 .chks64
  427. 1DE .data
  428. 94 .debug$S
  429. A8 .drectve
  430. 30 .pdata
  431. 60C .text$mn
  432. 28 .xdata