Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: c285ea287c02bfe0d7ad9f6ce9e5161c
Size: 703.49 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 c285ea287c02bfe0d7ad9f6ce9e5161c
Sha1 065ce5f39353df024af1981b8e125fb860a75d56
Sha256 120449b84850ba5b41e73f85e2f178271dd1cd0b8743f1e5af6ef760aa39b199
Sha384 5d97d2612acc48de118e3d7053dbe3dace971a549ab6f1bfb721f06392448e293c18b5cc9e1db586b1e0bbf79b9b86c5
Sha512 59396989e17011159e5ef16368d016d8ac641967777576c2fd9b9a8fa53edf9c755e29f1fc1223760d9267ea88da4ede768b73f5f9e8b59d8f63c510ae100831
SSDeep 12288:bNlcIQECHcsM7CZ3ujXztb1QYdkq/0ePNvuEvQBZY49deEb2:TQDHcxWAjX/QYCqLJBvQBOB
TLSH E8E4231122E1D06BD8BB2F7056F4D17643752DED9D21C2CE8EE82DCB3C85BA099A435B
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WindowsTips.Forms.MainForm.resources
WindowsTips.Properties.Resources.resources
LPP
[NBF]root.Data
Thinking
[NBF]root.Data
[NBF]root.Data-preview.png
Thinking_Spinner
[NBF]root.Data
[NBF]root.Data-preview.png
jpwn
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
jtLb.exe
Full Name
jtLb.exe
EntryPoint
System.Void WindowsTips.Program::Main()
Scope Name
jtLb.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
jtLb
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
191
Main Method
System.Void WindowsTips.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void WindowsTips.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
jtLb.exe
Full Name
jtLb.exe
EntryPoint
System.Void WindowsTips.Program::Main()
Scope Name
jtLb.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
jtLb
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
191
Main Method
System.Void WindowsTips.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void WindowsTips.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
PDB Path PATH
jthuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙