Suspicious
Suspect

PE Executable
MD5: 608da9f841a023fd6153eadd30e57ce7
Size: 673.79 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 608da9f841a023fd6153eadd30e57ce7
Sha1 00048a7876998a610128ad103b1c9c89f2281efe
Sha256 28c5e8b7d20d75a98b5a03259201fdb64fb6ac876eefd759f5536ef6ad3a098c
Sha384 2f48ac467266b5ead42581f1e4992df9faf1124015f089ae59d61c539964606db72661faf69501f445b9c9fb9d648555
Sha512 f7d3acc56fd67e46bf0e48fd0758b87df6d9a6a120194f5cb71bf5ff4fc70aefbc6b5881a33571f835d6b1c46284ea23e46156cea70d4c014369c78f166e70f8
SSDeep 12288:dcVbQSxcG9IXR55HXZFjVEGuo2/tO/XCifBqLzwr7IV8YQ+2bOxI:dchQSx3ihHZFjV2oStO/Si2Uov72bM
TLSH 26E4125033A5E903D11193F81AF0F17617B86C98A520E3568ECD6DEFB6F6F095C282A7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
matchingGame.Form1.resources
$this.Icon
[NBF]root.IconData
PIA
[NBF]root.Data
ofd1.TrayLocation
matchingGame.Properties.Resources.resources
NJqF
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\ZZCenmvDwq\src\obj\Debug\QbAK.pdb
Module Name
QbAK.exe
Full Name
QbAK.exe
EntryPoint
System.Void matchingGame.Program::Main()
Scope Name
QbAK.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
QbAK
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
215
Main Method
System.Void matchingGame.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void matchingGame.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
QbAK.exe
Full Name
QbAK.exe
EntryPoint
System.Void matchingGame.Program::Main()
Scope Name
QbAK.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
QbAK
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
215
Main Method
System.Void matchingGame.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void matchingGame.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
matchingGame.Form1.resources
$this.Icon
[NBF]root.IconData
PIA
[NBF]root.Data
ofd1.TrayLocation
matchingGame.Properties.Resources.resources
NJqF
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙