Suspicious
Suspect

d7c652c08d32714b0beaf991d26ca600

PE Executable
MD5: d7c652c08d32714b0beaf991d26ca600
Size: 580.1 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 d7c652c08d32714b0beaf991d26ca600
Sha1 67e6ebc692ba64c54e254ff6415733b8778eda7c
Sha256 ff319430f00da8eebd3b92f0d494c1dd9bee7f9ef3a8101dda2ce14968b9811a
Sha384 b8c652126870190cd089506627ae0146196d7f43297e6c42ece998453b76d15112ea741d8284475405fb6f6918d0af02
Sha512 656f4e6adf0dd2a17abc0a943b164c19c4575aba8f731b9f7c6dda8f88e9aa3d3b775379dbb044ae63aae87553d0883acbc1366a7adac6fba569c623d4b15ca5
SSDeep 12288:W8nl4S2PvH5+7E8nWgfR/49hWZOlL8MxPMsbhHE:hnKBvHkAsflGhOOl1xEsy
TLSH 01C4CF1076B98F02C8A7A7F45970E07107F46EAEAA21D30E8EE53DDB7279F914A41743
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Library.FormMenu.resources
$this.Icon
[NBF]root.IconData
TCA
[NBF]root.Data
Library.FormBook.resources
BookFlowLibrary.Properties.Resources.resources
prWQE
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
skTkQ.exe
Full Name
skTkQ.exe
EntryPoint
System.Void Library.Program::Main()
Scope Name
skTkQ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
skTkQ
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
759
Main Method
System.Void Library.Program::Main()
Main IL Instruction Count
5
Main IL
nop <null>
newobj System.Void Library.FormMenu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
skTkQ.exe
Full Name
skTkQ.exe
EntryPoint
System.Void Library.Program::Main()
Scope Name
skTkQ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
skTkQ
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
759
Main Method
System.Void Library.Program::Main()
Main IL Instruction Count
5
Main IL
nop <null>
newobj System.Void Library.FormMenu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
?huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Library.FormMenu.resources
$this.Icon
[NBF]root.IconData
TCA
[NBF]root.Data
Library.FormBook.resources
BookFlowLibrary.Properties.Resources.resources
prWQE
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
PDB Path PATH
?huhuhuhu
d7c652c08d32714b0beaf991d26ca600
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙