Suspicious
Suspect

5d293eb8be6f5b02de00c3838be03c6f

PE Executable
MD5: 5d293eb8be6f5b02de00c3838be03c6f
Size: 1.12 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 5d293eb8be6f5b02de00c3838be03c6f
Sha1 4f421aefe7c7dfcda6e4c7a743e7099be76465ba
Sha256 d7cae19dd4c3552a2a3ccde2b85fa2eae9feeedcfb9b793ea8e75b1e78344e99
Sha384 2d3a4132c060ebb1abdb7276c88ca3e29bd9e5973b36dabda077b9d22132e12148776dddeaa65f3da6e244b4097fe11c
Sha512 9843f26834760801a020ea2b2d38d10e22d0e163c7ade169999489c60cf865013016dca7101d23ac6e834cea129516a523d1a64ded3ac7cc932a609d3fb74509
SSDeep 24576:RR8gpGe3hLFN2DgxpGxT5XcxBEcpMIKdMxTcjr:RGgpb3hLFs8yxT5X2E2zdxTcn
TLSH 3F35F1701A08C982D9624BBBD921E6F937B51E74D830D3138AEBBDF7393575418E42B2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CoralReefApp.Properties.Resources.resources
Kare
[NBF]root.Data
SHWi
[NBF]root.Data
[NBF]root.Data-preview.png
CoralReefApp.StockForm.resources
$this.Icon
[NBF]root.IconData
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
cfOH.exe
Full Name
cfOH.exe
EntryPoint
System.Void CoralReefApp.Program::Main()
Scope Name
cfOH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
cfOH
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
243
Main Method
System.Void CoralReefApp.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void CoralReefApp.Program::InitialisiereDatenSet()
nop <null>
newobj System.Void CoralReefApp.ReefForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
cfOH.exe
Full Name
cfOH.exe
EntryPoint
System.Void CoralReefApp.Program::Main()
Scope Name
cfOH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
cfOH
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
243
Main Method
System.Void CoralReefApp.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void CoralReefApp.Program::InitialisiereDatenSet()
nop <null>
newobj System.Void CoralReefApp.ReefForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CoralReefApp.Properties.Resources.resources
Kare
[NBF]root.Data
SHWi
[NBF]root.Data
[NBF]root.Data-preview.png
CoralReefApp.StockForm.resources
$this.Icon
[NBF]root.IconData
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙