Suspicious
Suspect

459e5451e5cc84745ec80b4c847694bd

PE Executable
MD5: 459e5451e5cc84745ec80b4c847694bd
Size: 727.04 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 459e5451e5cc84745ec80b4c847694bd
Sha1 a5dcdb6fd43a3551026bebb3981afb9b0ac46c01
Sha256 bbd64c624d3ee6df910c2704ab3040d756550476cb446aaa6147cc4914f89ebe
Sha384 68a828f106c9b514da0a30cf7e23916f755d17ea8a858185f86f049962db503d66888d7fee56084dbb232253897d2f75
Sha512 459778990e3d2e7da22a8a2e81129b2ec6be3073e668025967a04d0adbda6283cfdf58ced8fb3397ed9677fcf76fa7a834cab8ecfacc799c2b4fe4cd3038cc95
SSDeep 12288:8A4N1zhhQ/ULkDoMBNlscRggT2lY5JcON5viqBjbm05oKwZIi:8lToULkDoMiY5JPN0qBjbm05oKBi
TLSH 9CF4CF1127B48925F5BF4BB56960C0300772BC26A4A2D359AAC5B9DF3D717C08EFA327
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DeviceMeasures.Forms.DeviceMeasurementDashboard.resources
DeviceMeasures.Forms.SystemConfigurationPanel.resources
$this.Icon
[NBF]root.IconData
DeviceMeasures.Forms.DeviceAboutDialog.resources
$this.Icon
[NBF]root.IconData
DeviceMeasures.Properties.Resources.resources
LPP
[NBF]root.Data
settings
[NBF]root.Data
[NBF]root.Data-preview.png
smile
[NBF]root.Data
[NBF]root.Data-preview.png
xWyv
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
TKKE.exe
Full Name
TKKE.exe
EntryPoint
System.Void DeviceMeasures.Program::Main()
Scope Name
TKKE.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
TKKE
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
798
Main Method
System.Void DeviceMeasures.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void DeviceMeasures.Forms.DeviceMeasurementDashboard::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
?huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DeviceMeasures.Forms.DeviceMeasurementDashboard.resources
DeviceMeasures.Forms.SystemConfigurationPanel.resources
$this.Icon
[NBF]root.IconData
DeviceMeasures.Forms.DeviceAboutDialog.resources
$this.Icon
[NBF]root.IconData
DeviceMeasures.Properties.Resources.resources
LPP
[NBF]root.Data
settings
[NBF]root.Data
[NBF]root.Data-preview.png
smile
[NBF]root.Data
[NBF]root.Data-preview.png
xWyv
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
PDB Path PATH
?huhuhuhu
459e5451e5cc84745ec80b4c847694bd
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙