Suspicious
Suspect

0634d014d43032342cce838b8516f581

PE Executable
MD5: 0634d014d43032342cce838b8516f581
Size: 3.27 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 0634d014d43032342cce838b8516f581
Sha1 f7fd28218daa88429ac0f0215b56a7f840b4d83b
Sha256 f137ebfc699dbff610cd6526a026a290d6cdd54b7aaa0c468a31a5e6cdcdce1b
Sha384 c614c4d9370ac75c41800b045b311aa1e716308e09f05b2bab7483f17e154c9f044d7f52cfbe107567e7c44f53e89cd9
Sha512 92904978ef01bfcd9b6028b7d1aa4a191c0bd75eb1b8a538be6e10738a777ddf090e7d9c20525a9e2cdb4a9babcd3dab085623b1dd6360a7522d95b79f8461bd
SSDeep 49152:nvwz92YpaQI6oPZlhP3Reybewo56RJ6WbR3LoGdikTHHB72eh2NT:nvq92YpaQI6oPZlhP3Yybewo56RJ6Q
TLSH 18E56B143BF85E27E1BBE677A5B0041267F0FC1AF363EB0B2581677A1C53B5098426A7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client
Full Name
Client
EntryPoint
System.Void 뭑⑮ꚋ紱穼꾖€㌵넠皯ހ呸꣰ꦦ蚟��癤::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 뭑⑮ꚋ紱穼꾖€㌵넠皯ހ呸꣰ꦦ蚟��癤::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 뭑⑮ꚋ紱穼꾖€㌵넠皯ހ呸꣰ꦦ蚟��癤::怶纑廟鴩⠅큌ꬋẗ㣒ᐖ㛷괚䅿໢끢銇ꩍ(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 뭑⑮ꚋ紱穼꾖€㌵넠皯ހ呸꣰ꦦ蚟��癤::ᐘ¤稯ꂴ罆巻呗⹉ᅌ悅⌮鴻冂ᖨ酜̴ὗꅅ(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 餉슻䘜醬䃒߈ꚦධﴐὪ骂恵䳜�䧉谕帓숯::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void 뭑⑮ꚋ紱穼꾖€㌵넠皯ހ呸꣰ꦦ蚟��癤::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 뭑⑮ꚋ紱穼꾖€㌵넠皯ހ呸꣰ꦦ蚟��癤::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 뭑⑮ꚋ紱穼꾖€㌵넠皯ހ呸꣰ꦦ蚟��癤::怶纑廟鴩⠅큌ꬋẗ㣒ᐖ㛷괚䅿໢끢銇ꩍ(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 뭑⑮ꚋ紱穼꾖€㌵넠皯ހ呸꣰ꦦ蚟��癤::ᐘ¤稯ꂴ罆巻呗⹉ᅌ悅⌮鴻冂ᖨ酜̴ὗꅅ(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 餉슻䘜醬䃒߈ꚦධﴐὪ骂恵䳜�䧉谕帓숯::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙