Suspicious
Suspect

3de985cb3c3427fff40ac76d48022231

PE Executable
MD5: 3de985cb3c3427fff40ac76d48022231
Size: 3.27 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 3de985cb3c3427fff40ac76d48022231
Sha1 c1305bc2f9d27f21c371f2c83d8d85c776da72d1
Sha256 b8d565ca8bb20cd435732cf0d0e6a327230dd3820deccedbc75b5a44e252e929
Sha384 efe16c9d83e37322828c0e5e1318406ad8658b19fef3880d3057d4e3759ad2ba9794068e3b8d91146f27c9b3ffe3a648
Sha512 3525b79af2f0b9e83ef6328faacbe7913d52909ce22fbea45418829cf9eb0959c39c4f24a57456ae7285d955592680722f9636fb22def872fbb1de062a33e733
SSDeep 49152:WvbI22SsaNYfdPBldt698dBcjHhw237ar7moGd9d2THHB72eh2NT:Wvk22SsaNYfdPBldt6+dBcjHf3h
TLSH 0DE54A1037F85E23E1ABE37395B0041767F1FC2AB3A3EB0B6191677A5C53B5049826A7
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client
Full Name
Client
EntryPoint
System.Void 섂뇉ጓ㜉㾃箱㺭覴竲ꑜ韋ᳳ銈㘍컟嗮ⱗ㮉뇳ﲹ::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 섂뇉ጓ㜉㾃箱㺭覴竲ꑜ韋ᳳ銈㘍컟嗮ⱗ㮉뇳ﲹ::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 섂뇉ጓ㜉㾃箱㺭覴竲ꑜ韋ᳳ銈㘍컟嗮ⱗ㮉뇳ﲹ::᭶ᠨ톕췣玴㣇紾᏾냍鴋ᅼ演⇊⮜粼셟(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 섂뇉ጓ㜉㾃箱㺭覴竲ꑜ韋ᳳ銈㘍컟嗮ⱗ㮉뇳ﲹ::춁蛽᯼充菆⟁顼觿䰚ඟ侄䕖섔ﺓ弹㽅ꙷ蓀(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 琜污臉凐ⴁ鱋⟬蒤곃㢟䐌篬໼ಷ丕::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void 섂뇉ጓ㜉㾃箱㺭覴竲ꑜ韋ᳳ銈㘍컟嗮ⱗ㮉뇳ﲹ::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 섂뇉ጓ㜉㾃箱㺭覴竲ꑜ韋ᳳ銈㘍컟嗮ⱗ㮉뇳ﲹ::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 섂뇉ጓ㜉㾃箱㺭覴竲ꑜ韋ᳳ銈㘍컟嗮ⱗ㮉뇳ﲹ::᭶ᠨ톕췣玴㣇紾᏾냍鴋ᅼ演⇊⮜粼셟(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 섂뇉ጓ㜉㾃箱㺭覴竲ꑜ韋ᳳ銈㘍컟嗮ⱗ㮉뇳ﲹ::춁蛽᯼充菆⟁顼觿䰚ඟ侄䕖섔ﺓ弹㽅ꙷ蓀(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 琜污臉凐ⴁ鱋⟬蒤곃㢟䐌篬໼ಷ丕::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙