Suspicious
Suspect

02801e6a414d5e2720c6a04cd6684bd0

PE Executable
MD5: 02801e6a414d5e2720c6a04cd6684bd0
Size: 617.98 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 02801e6a414d5e2720c6a04cd6684bd0
Sha1 924430a5673f31cc09b1f894a65df22dfaaec57d
Sha256 c237d2897a77f44f53d5a1e5b033ca2b7757601b9352b904c80a7415d85cf7fe
Sha384 377b8d44a0b063284722ec196eaba401018efe34442667a17b1cea08af34a15854d1594e663cac01663575a314210b0b
Sha512 1dadf467a03332e1da57caae31a732cec6c263b74b6bddae06a59f463b68eaa97eb39a457595a2ce914ec5ba950b537ccea7a05cc067ceba23997f247c940a73
SSDeep 12288:asJCzn2hin7jgJQSl9xGhPsxDNRgghT4rgB43bMm:aska87EyWJRgmkc+3bM
TLSH 96D412B11369DE11E9E12BF319B1D3B687B01D9EF011E20A8FDADCCB7156B149D443A2
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ConcentrationPair.FormSelecteurTheme.resources
ConcentrationPair.Properties.Resources.resources
JXDTQo
[NBF]root.Data
[NBF]root.Data-preview.png
NH
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: CyoLrd.pdb
Module Name
CyoLrd.exe
Full Name
CyoLrd.exe
EntryPoint
System.Void ConcentrationPair.Program::Main()
Scope Name
CyoLrd.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
CyoLrd
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
167
Main Method
System.Void ConcentrationPair.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ConcentrationPair.FormSelecteurTheme::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ConcentrationPair.FormSelecteurTheme.resources
ConcentrationPair.Properties.Resources.resources
JXDTQo
[NBF]root.Data
[NBF]root.Data-preview.png
NH
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙