Threat Database Trojans Trojan.MSIL.Blocker.RB

Trojan.MSIL.Blocker.RB

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,172
Threat Level: 80 % (High)
Infected Computers: 242
First Seen: August 31, 2023
Last Seen: October 6, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Blocker.RB
Signature status: Hash Mismatch

Known Samples

MD5: 218bf9394d4b2227a9a831b82030f276
SHA1: fc1daca15c6e77bc395ad1624663588815369316
SHA256: 843B46AC6A98353E6012824B5E0328C364545BB2ACA23B63BD16A98E239CD0BE
File Size: 3.88 MB, 3884368 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 12.13.7.1
Comments iTunes
Company Name Apple Inc.
File Description iTunes
File Version 12.13.7.1
Internal Name Mgtkewnppw.exe
Legal Copyright © 2000–2025 Apple Inc. All rights reserved.
Original Filename Mgtkewnppw.exe
Product Name iTunes
Product Version 12.13.7.1

Digital Signatures

Signer Root Status
Apple Inc. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch
Apple Inc. DigiCert Trusted Root G4 Hash Mismatch

File Traits

  • .NET
  • HighEntropy
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 6,432
Potentially Malicious Blocks: 220
Whitelisted Blocks: 4,835
Unknown Blocks: 1,377

Visual Map

x ? ? ? 0 0 ? ? ? ? 0 ? 0 ? ? 0 0 x ? 0 ? ? x x ? 0 x ? x ? ? 0 0 ? 0 x x ? x x x x x ? 0 0 ? 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 ? ? ? ? ? ? 0 ? x x x ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 ? ? 0 0 ? 0 0 ? ? x 0 x 0 ? ? ? x ? ? ? ? ? ? 0 ? ? ? ? 0 ? x 0 ? 0 0 0 0 0 0 x 0 0 ? 0 x 0 ? ? 0 ? ? ? ? 0 0 0 ? ? ? ? x 0 0 ? ? x 0 ? ? ? 0 ? 0 0 x 0 0 ? ? 0 ? 0 0 0 x ? ? ? 0 ? ? ? ? ? 0 ? x 0 0 ? ? 0 ? ? ? ? ? x ? 0 ? ? x ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 x 0 ? ? ? ? ? ? x ? 0 ? ? ? ? ? ? ? x ? 0 ? ? x ? 0 ? ? 0 0 ? x 0 ? ? ? 0 ? ? 0 0 0 ? 0 0 0 0 x ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? 0 0 0 ? ? ? 0 ? x 0 ? x x ? ? ? ? ? 0 ? ? ? ? ? x ? x ? 0 ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? 0 ? ? 0 x x x ? 0 0 ? x ? ? ? ? 0 ? 0 ? x ? ? ? ? ? ? 0 ? x x 0 ? 0 x 0 ? 0 0 0 0 ? ? ? 0 0 0 ? 0 ? 0 0 0 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? ? 0 ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? x ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? 0 ? 0 ? ? ? ? ? x ? ? 0 0 ? ? ? ? ? 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? 0 x ? ? ? ? ? ? 0 x 0 0 x 0 0 ? ? x 0 ? 0 0 0 0 0 0 0 0 ? ? x ? ? 0 x ? x x x ? x 0 x x 0 0 ? ? 0 0 0 0 0 x x x x 0 0 0 ? ? ? 0 0 ? ? ? x x ? x ? ? ? ? ? ? 0 0 ? x ? ? ? 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? x ? ? x x x x ? ? ? ? ? x x x x ? ? ? ? ? ? ? x ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 x ? ? x ? ? ? ? ? ? ? x x x x x ? ? x x ? ? x x ? ? x x x ? x x x x x x x ? x x x ? x x x x x x ? ? ? ? x x x x ? ? ? ? ? ? ? ? ? x x x 0 ? ? ? ? 0 ? ? ? ? ? x ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? x x ? ? ? ? ? x ? ? ? x 0 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 0 0 0 0 0 ? 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? x 0 0 ? 0 ? ? 0 0 0 0 ? 0 ? 0 x 0 x x ? ? ? ? ? ? ? ? ? ? ? ? ? x x ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\startup\smdll.vbs Generic Write,Read Attributes
c:\users\user\appdata\roaming\smdll.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Anti Debug
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges
Process Terminate
  • TerminateProcess

Trending

Most Viewed

Loading...