Suspicious
Suspect

0da3d6163e946124e407772e5bbffd31

PE Executable
MD5: 0da3d6163e946124e407772e5bbffd31
Size: 730.11 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 0da3d6163e946124e407772e5bbffd31
Sha1 20e3e72278a83202571e2f88ccd0813dd82bce14
Sha256 f00ddfca55cd75dc518bbddafd3f5c7327916d430fb2575e3c87cf93ac5c2db8
Sha384 b72e20d8dcaac6600f80340e813a56920e9294189ef5a5aa08f05a50a67faae5df1a2c620ef3d01b6c76a481f5e25abc
Sha512 8fbc582af7d04306e5896fd86f3da332a883299d14a79d66b0e4856448d1885894dd27b2432830b07ea4bb04bf4f046bf6e156f40f3e3d6fda9272946962f0ac
SSDeep 12288:EerChncufNfhD/JgnTpPD9LoMWwabGaPAKxZux0Eg+Tp1eW76T:Ee8V9J/JQlxLoypaPA2ux0nWeWe
TLSH F1F412541606D907D9E227F45CF2E3B845985ECAB800D6136FFABCB7B93A319A6D43C0
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SmartNotesApp.Properties.Resources.resources
GgDI
[NBF]root.Data
[NBF]root.Data-preview.png
htta
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: QEQD.pdb
Module Name
QEQD.exe
Full Name
QEQD.exe
EntryPoint
System.Void SmartNotesApp.Program::Main()
Scope Name
QEQD.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
QEQD
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
76
Main Method
System.Void SmartNotesApp.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SmartNotesApp.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
QEQD.exe
Full Name
QEQD.exe
EntryPoint
System.Void SmartNotesApp.Program::Main()
Scope Name
QEQD.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
QEQD
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
76
Main Method
System.Void SmartNotesApp.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SmartNotesApp.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SmartNotesApp.Properties.Resources.resources
GgDI
[NBF]root.Data
[NBF]root.Data-preview.png
htta
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙