Suspicious
Suspect

47faf7750cf003e0f64ea3fea9c44b39

PE Executable
MD5: 47faf7750cf003e0f64ea3fea9c44b39
Size: 3.58 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 47faf7750cf003e0f64ea3fea9c44b39
Sha1 28da3d835fd85a66c11f05fa3fd8a0d6ecc3e65d
Sha256 1066003052bf79de8ab4f07bb7ff3dc980a8622b9175ef714a6df5dd01d517b7
Sha384 c1a319f9ce90f9a4dd292f105c2a371c5e7582a65407a8bd484412dad4994b14ce8195303867443900d249a55f1c2fd8
Sha512 322a4d7670695645d66e70541d5e974297c42b1c613a4fed90e943efd63f628fc648ec4240fee84e091bdd10317bdcde1c6786116c683dc24ade4be7ce3a35c2
SSDeep 49152:K8vRXihMNzYBq5Ry/z/4TWHjjScaGHHBT2ehYnTf:KU1yc5Ry/z1CR
TLSH 9BF57C1877FC5F2AE47F97B1E1B0101267F1F82EF363EB4A1181667A2962751884237B
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client
Full Name
Client
EntryPoint
System.Void ㄧᆭ䁁鍖葪꺽猄냫㠷ꑛ䂙瘀粘홄᷅긆撚跤::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6.1
Total Strings
14204
Main Method
System.Void ㄧᆭ䁁鍖葪꺽猄냫㠷ꑛ䂙瘀粘홄᷅긆撚跤::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void ㄧᆭ䁁鍖葪꺽猄냫㠷ꑛ䂙瘀粘홄᷅긆撚跤::␕蹢⬣糰෎煽ꨵ琺欹䠺誂ᗞ㳔⋫裏江睫⭳釧⨒(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void ㄧᆭ䁁鍖葪꺽猄냫㠷ꑛ䂙瘀粘홄᷅긆撚跤::麚Ꮈ掆쳴䟁堠黿漳彺睕휒릦豉릆Ს聚蘙帓�(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 檜邺毣䆉޼ᙌ�䛨ᅪ睭혫蛊�숊眊꥙�::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void ㄧᆭ䁁鍖葪꺽猄냫㠷ꑛ䂙瘀粘홄᷅긆撚跤::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6.1
Total Strings
14204
Main Method
System.Void ㄧᆭ䁁鍖葪꺽猄냫㠷ꑛ䂙瘀粘홄᷅긆撚跤::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void ㄧᆭ䁁鍖葪꺽猄냫㠷ꑛ䂙瘀粘홄᷅긆撚跤::␕蹢⬣糰෎煽ꨵ琺欹䠺誂ᗞ㳔⋫裏江睫⭳釧⨒(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void ㄧᆭ䁁鍖葪꺽猄냫㠷ꑛ䂙瘀粘홄᷅긆撚跤::麚Ꮈ掆쳴䟁堠黿漳彺睕휒릦豉릆Ს聚蘙帓�(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 檜邺毣䆉޼ᙌ�䛨ᅪ睭혫蛊�숊眊꥙�::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙