PUP.MSIL.BadJoke.NB

Analysis Report

General information

Family Name: PUP.MSIL.BadJoke.NB
Signature status: No Signature

Known Samples

MD5: 16dc4a3fff08f648eadf5c6f12520d68
SHA1: 3e7c0857e10137d627a02aa6d0f78093f2a6ee43
SHA256: 6351FC20FBAF4150D2F98BDF617697AEDCEC8AB0648AE32A5FF7EA1600707E0F
File Size: 25.60 KB, 25600 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description winx
File Version 1.0.0.0
Internal Name winx.exe
Legal Copyright Copyright © 2024
Original Filename winx.exe
Product Name winx
Product Version 1.0.0.0

File Traits

  • .NET
  • HighEntropy
  • ntdll
  • x86

Block Information

Total Blocks: 9
Potentially Malicious Blocks: 2
Whitelisted Blocks: 7
Unknown Blocks: 0

Visual Map

0 x 0 x 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Coinminer.XA
  • MSIL.Coinminer.XB
  • MSIL.Coinminer.XC

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider

Trending

Most Viewed

Loading...