Suspicious
Suspect

PE Executable
MD5: b0200705aeb8d472660a0c7e8a553347
Size: 1.08 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 b0200705aeb8d472660a0c7e8a553347
Sha1 aba2f7a0dbf1dd9ee86960fe9d6109e494dba69e
Sha256 75cc0d7abb4cb0145f0dc0639fbee4be7925dd45a38664e063095963c482ea78
Sha384 ff3a9ce28109c555db12fae129d28bb2bfac3e2e2bf3ed3f76e22ca001230ab6f8daffa5c1bd5018c2db368fc1598125
Sha512 b959b75b4f4889e11b8a054e838f5c159ed0a190dabe7198afaffbe067739d07a422fc0f2fbd620dd49c70e8cd844a1167a34498cb5f681e0f96f180e2f019f2
SSDeep 24576:b7Uk7CN7WP4HVfxpGsRdmxdWUSgwU62iwRtPQ96PdP:U17WgHVfxphRE5SgwUAk+6Pd
TLSH 3F35120422ADC74AD97B9FF48421E1706779ACBE7911D2469FCE3CDBB43AB25841A703
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TabManager.Properties.Resources.resources
APPLE_GREEN
[NBF]root.Data
[NBF]root.Data-preview.png
Solve
[NBF]root.Data
dBWofXP
[NBF]root.Data
[NBF]root.Data-preview.png
images__1_
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
CriticalHandleZeroOrMinusOneIsInva
Full Name
CriticalHandleZeroOrMinusOneIsInva
EntryPoint
System.Void TextI.MLangCodePageEncod::Main()
Scope Name
CriticalHandleZeroOrMinusOneIsInva
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ljpBwxN
Assembly Version
2.7.1.7
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
349
Main Method
System.Void TextI.MLangCodePageEncod::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Regis.Cl::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
CriticalHandleZeroOrMinusOneIsInva
Full Name
CriticalHandleZeroOrMinusOneIsInva
EntryPoint
System.Void TextI.MLangCodePageEncod::Main()
Scope Name
CriticalHandleZeroOrMinusOneIsInva
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ljpBwxN
Assembly Version
2.7.1.7
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
349
Main Method
System.Void TextI.MLangCodePageEncod::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Regis.Cl::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TabManager.Properties.Resources.resources
APPLE_GREEN
[NBF]root.Data
[NBF]root.Data-preview.png
Solve
[NBF]root.Data
dBWofXP
[NBF]root.Data
[NBF]root.Data-preview.png
images__1_
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙