Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: b0200705aeb8d472660a0c7e8a553347
Size: 1.08 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 b0200705aeb8d472660a0c7e8a553347
Sha1 aba2f7a0dbf1dd9ee86960fe9d6109e494dba69e
Sha256 75cc0d7abb4cb0145f0dc0639fbee4be7925dd45a38664e063095963c482ea78
Sha384 ff3a9ce28109c555db12fae129d28bb2bfac3e2e2bf3ed3f76e22ca001230ab6f8daffa5c1bd5018c2db368fc1598125
Sha512 b959b75b4f4889e11b8a054e838f5c159ed0a190dabe7198afaffbe067739d07a422fc0f2fbd620dd49c70e8cd844a1167a34498cb5f681e0f96f180e2f019f2
SSDeep 24576:b7Uk7CN7WP4HVfxpGsRdmxdWUSgwU62iwRtPQ96PdP:U17WgHVfxphRE5SgwUAk+6Pd
TLSH 3F35120422ADC74AD97B9FF48421E1706779ACBE7911D2469FCE3CDBB43AB25841A703
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TabManager.Properties.Resources.resources
APPLE_GREEN
[NBF]root.Data
[NBF]root.Data-preview.png
Solve
[NBF]root.Data
dBWofXP
[NBF]root.Data
[NBF]root.Data-preview.png
images__1_
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
CriticalHandleZeroOrMinusOneIsInva
Full Name
CriticalHandleZeroOrMinusOneIsInva
EntryPoint
System.Void TextI.MLangCodePageEncod::Main()
Scope Name
CriticalHandleZeroOrMinusOneIsInva
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ljpBwxN
Assembly Version
2.7.1.7
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
349
Main Method
System.Void TextI.MLangCodePageEncod::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Regis.Cl::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
CriticalHandleZeroOrMinusOneIsInva
Full Name
CriticalHandleZeroOrMinusOneIsInva
EntryPoint
System.Void TextI.MLangCodePageEncod::Main()
Scope Name
CriticalHandleZeroOrMinusOneIsInva
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ljpBwxN
Assembly Version
2.7.1.7
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
349
Main Method
System.Void TextI.MLangCodePageEncod::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Regis.Cl::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙