Suspicious
Suspect

PE Executable
MD5: 22fdcda59eb88488ac0f3a9c33c8de71
Size: 3.27 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 22fdcda59eb88488ac0f3a9c33c8de71
Sha1 b9db244b9808a70fe0bda89410261d03d2f3404b
Sha256 716a0a7af8fbbb64bb59316b86ba3313ac7b4669d15845365985c2193f007eee
Sha384 7242f4899d9d0ff07bdf03292b737f560ef2c1080edb7f1af04c58d62218e7966d1b12b5d7e220c89bba8b9eb569163a
Sha512 2e5bd029aa5a8d778656924d71caab1d430c5f4113757ffda6898348b68ac14dd959e8f15e4ff437e06f5a7d8dbc671e227b0d9567645eb57aacace587049f8c
SSDeep 49152:qvvI22SsaNYfdPBldt698dBcjHgtbR35oGd+RTHHB72eh2NT:qvg22SsaNYfdPBldt6+dBcjHg9
TLSH 81E55A1437F85F23E1BBE27396B0041267F0EC1AB3A3F74B658167791C93B505942AAB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client
Full Name
Client
EntryPoint
System.Void уꏶ㆓㖡≔톘㹟꿷옆䨻࿒慇졏弽픠싹᠃::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void уꏶ㆓㖡≔톘㹟꿷옆䨻࿒慇졏弽픠싹᠃::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void уꏶ㆓㖡≔톘㹟꿷옆䨻࿒慇졏弽픠싹᠃::ጂ෪ୌ蒍ہ╡훣腘ឈễ㣎믘��剃튬᪙ꇿ㩳(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void уꏶ㆓㖡≔톘㹟꿷옆䨻࿒慇졏弽픠싹᠃::깈끃屺鸼︸朗䞫采埝혊৕↥햾)㇐㩜妏꘳ꈌ(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 샤⩢ー┮ކ畸揎륖䘒䓸椻爨뚙ྯ兽ꥂ䄹姂::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void уꏶ㆓㖡≔톘㹟꿷옆䨻࿒慇졏弽픠싹᠃::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void уꏶ㆓㖡≔톘㹟꿷옆䨻࿒慇졏弽픠싹᠃::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void уꏶ㆓㖡≔톘㹟꿷옆䨻࿒慇졏弽픠싹᠃::ጂ෪ୌ蒍ہ╡훣腘ឈễ㣎믘��剃튬᪙ꇿ㩳(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void уꏶ㆓㖡≔톘㹟꿷옆䨻࿒慇졏弽픠싹᠃::깈끃屺鸼︸朗䞫采埝혊৕↥햾)㇐㩜妏꘳ꈌ(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 샤⩢ー┮ކ畸揎륖䘒䓸椻爨뚙ྯ兽ꥂ䄹姂::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙