Suspicious
Suspect

2c53b36d9022bca33472d335d3e187cc

PE Executable
MD5: 2c53b36d9022bca33472d335d3e187cc
Size: 3.27 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 2c53b36d9022bca33472d335d3e187cc
Sha1 5b925ba0885fb3677a72ef608ee429bf668a86f1
Sha256 e67b2183d29858ca00445a85b172dfdab97b02d9eb0731daaf56cf485620ebc0
Sha384 ba7a563a0188382c1885b9d8316131d8e89ee619ab24cedaca750c5ed564b2c9b709e6badc5cb751f87b302c01f1dab2
Sha512 a67e2e67094971a0994f17518482685a9646b66d0cc02b85250d515e4239afc04b3f6b4eb586189ccc5e43da1fee262d6e23a01062379cf7195b64972db7ae3f
SSDeep 49152:Lv2I22SsaNYfdPBldt698dBcjHM7eiEwaak/sifoGd9bTHHB72eh2NT:Lvb22SsaNYfdPBldt6+dBcjHM7eKa
TLSH B4E55B1437F85F33E5BAE27395B0401667F0EC2AB3A3EB1B6191677E1C53B4058426AB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client
Full Name
Client
EntryPoint
System.Void 镦쭣宕曖呅际䳁劚얞樘膏桚嫮⮢쁥Ѻ߫鲬⍭쥲::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 镦쭣宕曖呅际䳁劚얞樘膏桚嫮⮢쁥Ѻ߫鲬⍭쥲::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 镦쭣宕曖呅际䳁劚얞樘膏桚嫮⮢쁥Ѻ߫鲬⍭쥲::璐梁ᵱ滦ᔄ⦳ﶡ囫檔잎薊ច쏔麗悜ȋ侎垻(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 镦쭣宕曖呅际䳁劚얞樘膏桚嫮⮢쁥Ѻ߫鲬⍭쥲::ጢ邆瓙靬䶶ェꦱ챲ഌ撛䔛縜㤍佔顎왦嫌ᑆ(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 읿溹ẁ᪶젌ㇼ릳薏뼱佲璊뿤㐹䪊⥿몲䗆験ࢨ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void 镦쭣宕曖呅际䳁劚얞樘膏桚嫮⮢쁥Ѻ߫鲬⍭쥲::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 镦쭣宕曖呅际䳁劚얞樘膏桚嫮⮢쁥Ѻ߫鲬⍭쥲::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 镦쭣宕曖呅际䳁劚얞樘膏桚嫮⮢쁥Ѻ߫鲬⍭쥲::璐梁ᵱ滦ᔄ⦳ﶡ囫檔잎薊ច쏔麗悜ȋ侎垻(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 镦쭣宕曖呅际䳁劚얞樘膏桚嫮⮢쁥Ѻ߫鲬⍭쥲::ጢ邆瓙靬䶶ェꦱ챲ഌ撛䔛縜㤍佔顎왦嫌ᑆ(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 읿溹ẁ᪶젌ㇼ릳薏뼱佲璊뿤㐹䪊⥿몲䗆験ࢨ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙