Suspicious
Suspect

98a29f93295ba4d70fb0e766b1fb0572

PE Executable
MD5: 98a29f93295ba4d70fb0e766b1fb0572
Size: 573.44 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 98a29f93295ba4d70fb0e766b1fb0572
Sha1 885ac21b684ab520b2615aef9c78b4c01844ce9f
Sha256 ebc963782a30a3e6cc360a6e4fda16d2acac2de13ee0d8db863082e699dabd5a
Sha384 28342574472d992a51093da152a32bfb224632cc0923004b8bbd677fb9d8ff1d1111df5d90b04a12e9aff639cb6d0c4a
Sha512 a2ed01d0d12b375e4c984101b8978a6e5bb613ec2bfdb2925e1880cd9d0b79045a40ed9c4cb088146779e4e4fddaf00c908b4c0c96f38be6a39e104641eb33bd
SSDeep 12288:7sttcH+j/wrhlbz5AxwikQhLn4MVot0K3U20pYGUa09F:7srcH4DzDK3U20pYK09
TLSH 46C41290396DCA17C1B31BF95A61D13017B93DAEA419D24B0FD6ADEF74AEB80634130B
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
KeyboardIndicator.Forms.MainForm.resources
KeyboardIndicator.Properties.Resources.resources
HviA
[NBF]root.Data
[NBF]root.Data-preview.png
SC
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: QBFD.pdb
Module Name
QBFD.exe
Full Name
QBFD.exe
EntryPoint
System.Void KeyboardIndicator.Program::Main()
Scope Name
QBFD.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
QBFD
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
142
Main Method
System.Void KeyboardIndicator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void KeyboardIndicator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
QBFD.exe
Full Name
QBFD.exe
EntryPoint
System.Void KeyboardIndicator.Program::Main()
Scope Name
QBFD.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
QBFD
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
142
Main Method
System.Void KeyboardIndicator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void KeyboardIndicator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
KeyboardIndicator.Forms.MainForm.resources
KeyboardIndicator.Properties.Resources.resources
HviA
[NBF]root.Data
[NBF]root.Data-preview.png
SC
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙