Suspicious
Suspect

PE Executable
MD5: 0547b2ee604c51ef6362e79ef5e26ff1
Size: 3.27 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 0547b2ee604c51ef6362e79ef5e26ff1
Sha1 d95edbff64a44cfbbfb6b90f4f603aed96005a62
Sha256 808ff595ff2b821ea1df1d62dbd214bdfc6d58aaf2f63b208ff3713ff43e14dd
Sha384 57b2935b7cfcfbbe869891c1d7c8fb62f378d15925d7dc217cccdfb974c0b0eeaab02145bb7c3d02bb1cd15e9d9b28a2
Sha512 ce733cff0c020c225335765202ec72a1e8c5b3ff22c315902b414174fd0cacfa5da09cdbe9067926a7492fde99b1442f6d467aa42ba541891838a07896009d8f
SSDeep 49152:mvkI22SsaNYfdPBldt698dBcjHXhq6vDmzaCoGd+fTHHB72eh2NT:mvJ22SsaNYfdPBldt6+dBcjHxq6vw
TLSH EEE55A0477F85E62E56BD3B2D5F0542363F0F82AF3A3EB0B5191677A1C93B4098426A7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client
Full Name
Client
EntryPoint
System.Void ᛭ၡ毌롇І梧텈泵쀤䝗奈䣉濘䲉埻钒::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void ᛭ၡ毌롇І梧텈泵쀤䝗奈䣉濘䲉埻钒::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void ᛭ၡ毌롇І梧텈泵쀤䝗奈䣉濘䲉埻钒::꺸됇ⲫ��⫞眨ꐰ뷅⪱톃瀊蟰떬ⲻ쉰꒔讎(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void ᛭ၡ毌롇І梧텈泵쀤䝗奈䣉濘䲉埻钒::胒畻訍⥁햨韊櫽꽅㖉嗄ꚻ걱遛鸝ᐟ첔潸ኺ(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 䐂⃍஋㍂耈闡ⴲ䕃嬜師ღ䋡멑傪鱱㈗涫蟩::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void ᛭ၡ毌롇І梧텈泵쀤䝗奈䣉濘䲉埻钒::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void ᛭ၡ毌롇І梧텈泵쀤䝗奈䣉濘䲉埻钒::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void ᛭ၡ毌롇І梧텈泵쀤䝗奈䣉濘䲉埻钒::꺸됇ⲫ��⫞眨ꐰ뷅⪱톃瀊蟰떬ⲻ쉰꒔讎(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void ᛭ၡ毌롇І梧텈泵쀤䝗奈䣉濘䲉埻钒::胒畻訍⥁햨韊櫽꽅㖉嗄ꚻ걱遛鸝ᐟ첔潸ኺ(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 䐂⃍஋㍂耈闡ⴲ䕃嬜師ღ䋡멑傪鱱㈗涫蟩::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙