Suspicious
Suspect

77419b9de019b422054b6560b7114441

PE Executable
MD5: 77419b9de019b422054b6560b7114441
Size: 935.94 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 77419b9de019b422054b6560b7114441
Sha1 d134cef036d35cdf137f08c7f8e838cedba7825c
Sha256 d05986e4e8a5d6818ae373894b7af0e78fddd99c57d1b3b76357dfcafefc0cbb
Sha384 4a28c06398b9181457252553523921de6cef8d9b1f8a8c94b6602bb9dee8ecab8c56e47fc717283de34ea843a0a24ab4
Sha512 b159b97f26c449d355672c323edd2f80e908852cb2ff943bec4f8d083645aa822f308caf8ce992c7bfbb880effc77fde5833a7b7295fbf4f6c63183169123704
SSDeep 12288:JPhRpqGkf4UfZNMywMadCJPzLes3t1fxSGWo31V/nbqRyoifTyrirJ1Pf:bR0wUfZbPGW/buuOIJ1Pf
TLSH A815E0701A04D981D5525BBBD921E3F837B46DB8D831D2138EEBBDBB783674018E52B2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CoralReefApp.Properties.Resources.resources
Kare
[NBF]root.Data
Qlly
[NBF]root.Data
[NBF]root.Data-preview.png
CoralReefApp.StockForm.resources
$this.Icon
[NBF]root.IconData
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Ctgy.exe
Full Name
Ctgy.exe
EntryPoint
System.Void CoralReefApp.Program::Main()
Scope Name
Ctgy.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Ctgy
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
243
Main Method
System.Void CoralReefApp.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void CoralReefApp.Program::InitialisiereDatenSet()
nop <null>
newobj System.Void CoralReefApp.ReefForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
Ctgy.exe
Full Name
Ctgy.exe
EntryPoint
System.Void CoralReefApp.Program::Main()
Scope Name
Ctgy.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Ctgy
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
243
Main Method
System.Void CoralReefApp.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void CoralReefApp.Program::InitialisiereDatenSet()
nop <null>
newobj System.Void CoralReefApp.ReefForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CoralReefApp.Properties.Resources.resources
Kare
[NBF]root.Data
Qlly
[NBF]root.Data
[NBF]root.Data-preview.png
CoralReefApp.StockForm.resources
$this.Icon
[NBF]root.IconData
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙