Suspicious
Suspect

2f6d0c6a6797793678b2a1b601cb2cad

PE Executable
MD5: 2f6d0c6a6797793678b2a1b601cb2cad
Size: 881.66 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 2f6d0c6a6797793678b2a1b601cb2cad
Sha1 4f908945bd414f1d9f349aeab88ca55ada8351cd
Sha256 e7a7b1d0ebf9cbb2760f3795b42b1b39596ab0eabf1cb12417ba2e8e42494708
Sha384 83ed0ff84d57ecb161813b174367a19a25d9847cb5c498aa41095991d77a2b44257796fef7fe32933f4325d620e542aa
Sha512 b9adaa8c15ded139d4dde8110a4122ab946faef631e8395f7d2983f6e80119ae04527b076be1c893098813bfeb8c2bc743cdb9bebb08be883608a8d4c0f7b792
SSDeep 24576:WAZoY82CkCAkcyW6A5Rx5lEr34J3z3KqDVfEBYF:WAZXf7kcyMDlJ3z6qD9G
TLSH D71523A12368CA23C48027F19936C2B953B42E4EA403D26B8FDCCEDBBD57F429D54719
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ConcentrationPair.FormSelecteurTheme.resources
ConcentrationPair.Properties.Resources.resources
NH
[NBF]root.Data
zaZFVu
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: LymtNv.pdb
Module Name
LymtNv.exe
Full Name
LymtNv.exe
EntryPoint
System.Void ConcentrationPair.Program::Main()
Scope Name
LymtNv.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
LymtNv
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
167
Main Method
System.Void ConcentrationPair.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ConcentrationPair.FormSelecteurTheme::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
LymtNv.exe
Full Name
LymtNv.exe
EntryPoint
System.Void ConcentrationPair.Program::Main()
Scope Name
LymtNv.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
LymtNv
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
167
Main Method
System.Void ConcentrationPair.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ConcentrationPair.FormSelecteurTheme::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ConcentrationPair.FormSelecteurTheme.resources
ConcentrationPair.Properties.Resources.resources
NH
[NBF]root.Data
zaZFVu
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙