Suspect
PE Executable
MD5: 7f77ccd9bc0b786ae2e1f1bfdd16915d
Size: 1.14 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 7f77ccd9bc0b786ae2e1f1bfdd16915d |
| Sha1 | 75a2ad8b237365ab3c892e3e87544f28ebd97b7a |
| Sha256 | e4b64ae324a75568f82dd940c4017726c020051668cbb1832e88f4e806abe4e4 |
| Sha384 | 525e20a6f449fc1bbabc1e9e52d52fcedbba7cf8d2c9b5c1100c5d3eb3c936d13b94e438d2d1897aa273e8dd79aa3112 |
| Sha512 | c4e49781d18d51e936ef9219897d486a12164b52aa74c4a0cdf1cbf646d51fc94201c29a37f697f46fb903abbac1549fa64d6bbcd33f0c69942ac631f010806b |
| SSDeep | 12288:ywEGvUhzbgQTBm4hScAKSDo684pO+A9lKr/vFLvVtgdSNTgKMHjOmrvuSINiDs:ywDUhQ0REv868MOT9lOdM/mNi |
| TLSH | 57350251BF08C513C06E1AF68AFAF53802B64CA65501D1375AE5BDAF3DBEFC258246B0 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
| Name | Value |
|---|---|
| Module Name | sQkd.exe |
| Full Name | sQkd.exe |
| EntryPoint | System.Void NotepadPlus.Program::Main(System.String[]) |
| Scope Name | sQkd.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | sQkd |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 203 |
| Main Method | System.Void NotepadPlus.Program::Main(System.String[]) |
| Main IL Instruction Count | 52 |
| Main IL | |
| Module Name | sQkd.exe |
| Full Name | sQkd.exe |
| EntryPoint | System.Void NotepadPlus.Program::Main(System.String[]) |
| Scope Name | sQkd.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | sQkd |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 203 |
| Main Method | System.Void NotepadPlus.Program::Main(System.String[]) |
| Main IL Instruction Count | 52 |
| Main IL | |
PDB Path
PATH
sQhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential