Suspicious
Suspect

PE Executable
MD5: 156280dc98ce13fddb21fac49dcff002
Size: 3.27 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 156280dc98ce13fddb21fac49dcff002
Sha1 dfae4d7db0fd05688f4c57427716ea634760fc1a
Sha256 1888dad764c782fdb3d8cfce0916fd197e645231f3cdc28e4d45d1558a0935db
Sha384 7843260f3280897a0b9733af6a89cb139f7ae0db5abdd6855ee189cdb42f2c5063ad7be9162009f1336f11c7d9ed37a2
Sha512 67f6a4771e8be87251c9ba2eb7d32aa9f9c2ed5b7140434c080aebef643b7079d51bd4c648f0239918bd5b02ea6374c2e379c950b60b2efa336b9802da5006bd
SSDeep 49152:evkt62XlaSFNWPjljiFa2RoUYIhg5qihwoGdQEBTHHB72eh2NT:ev462XlaSFNWPjljiFXRoUYIC5qie
TLSH 94E56B0437F85E72E16BD7B3E5B0501263F1F82AF363EB0B5181A77A5C93B5488426A7
PeID
.NET executableMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client
Full Name
Client
EntryPoint
System.Void ⬧僽᣹룐㳦搼䬯봎Ⱓధ끢᡿䥾᮲䖄①ꝗ::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void ⬧僽᣹룐㳦搼䬯봎Ⱓధ끢᡿䥾᮲䖄①ꝗ::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void ⬧僽᣹룐㳦搼䬯봎Ⱓధ끢᡿䥾᮲䖄①ꝗ::尜颡㺝窉⏢뫪듛ݮ엥⧫⊪첶깬僮ᶑ稼⍙ܸ(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void ⬧僽᣹룐㳦搼䬯봎Ⱓధ끢᡿䥾᮲䖄①ꝗ::攦跩�ਜꌓ䂲졝乢壬뢣麚᥹穳旁쑽ꐘ⇧樧ℇ뮲(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 쬞뛈桌⮀氎䯫蟌㿣拵ኆהּ㛅u檾䝀珝컜鹁槡돉::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void ⬧僽᣹룐㳦搼䬯봎Ⱓధ끢᡿䥾᮲䖄①ꝗ::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void ⬧僽᣹룐㳦搼䬯봎Ⱓధ끢᡿䥾᮲䖄①ꝗ::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void ⬧僽᣹룐㳦搼䬯봎Ⱓధ끢᡿䥾᮲䖄①ꝗ::尜颡㺝窉⏢뫪듛ݮ엥⧫⊪첶깬僮ᶑ稼⍙ܸ(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void ⬧僽᣹룐㳦搼䬯봎Ⱓధ끢᡿䥾᮲䖄①ꝗ::攦跩�ਜꌓ䂲졝乢壬뢣麚᥹穳旁쑽ꐘ⇧樧ℇ뮲(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 쬞뛈桌⮀氎䯫蟌㿣拵ኆהּ㛅u檾䝀珝컜鹁槡돉::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙