Suspicious
Suspect

c7c613a0bd28cc5b344d21e16c0d1f58

PE Executable
MD5: c7c613a0bd28cc5b344d21e16c0d1f58
Size: 1.14 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 c7c613a0bd28cc5b344d21e16c0d1f58
Sha1 b511b3d773d5755c0d156fa17c8cd92d55d3873f
Sha256 06fe9a22b45bfa76d0d8ae47a98525701494e47beae12cb13bca3dbf3b626315
Sha384 387a473e38ff6d3df21fef2fc5ae7f39aab58a88fb80c8d674c8bfa3de9320e35932b4b05057f927130b7084676f5ead
Sha512 d871b30899abb1f85ffabbe9b00b54fae6389161e08ce3c086464ec6fd2a44df38c7265e7b6a3becfb8d3b69a174b8ceb3e4711a14d5998e4882a9249606cef4
SSDeep 24576:rR0+xgsxr5pDk+FrCWdmoehLKCb7LBKzpikQ:rPKyr5pDkqrCFXbgtikQ
TLSH 5135F1702A05D982C8524BBBD960D3F837B56D74E831C2134EE7BDBB793671428E52B2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CoralReefApp.Properties.Resources.resources
Kare
[NBF]root.Data
niXG
[NBF]root.Data
[NBF]root.Data-preview.png
CoralReefApp.StockForm.resources
$this.Icon
[NBF]root.IconData
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
QKaF.exe
Full Name
QKaF.exe
EntryPoint
System.Void CoralReefApp.Program::Main()
Scope Name
QKaF.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
QKaF
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
243
Main Method
System.Void CoralReefApp.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void CoralReefApp.Program::InitialisiereDatenSet()
nop <null>
newobj System.Void CoralReefApp.ReefForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
QKaF.exe
Full Name
QKaF.exe
EntryPoint
System.Void CoralReefApp.Program::Main()
Scope Name
QKaF.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
QKaF
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
243
Main Method
System.Void CoralReefApp.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void CoralReefApp.Program::InitialisiereDatenSet()
nop <null>
newobj System.Void CoralReefApp.ReefForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CoralReefApp.Properties.Resources.resources
Kare
[NBF]root.Data
niXG
[NBF]root.Data
[NBF]root.Data-preview.png
CoralReefApp.StockForm.resources
$this.Icon
[NBF]root.IconData
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙