Suspicious
Suspect

499b589acc9357b036e678699948270d

PE Executable
MD5: 499b589acc9357b036e678699948270d
Size: 3.27 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 499b589acc9357b036e678699948270d
Sha1 e78369b59597fa1bd39a765972a8ef0878a926ed
Sha256 be5370686c2c4b8f69d7428ec4d7f5270ef6e8d6ea45b6846e3589bc289f69e9
Sha384 1d83d9f60f7cabdc4599fcfb9450c465a2e2ecf5e2e5d7ef2158de008c4dea378af6328b08c63267bdbd641990499dd9
Sha512 f5f816c423c71188d815058c0a2348a7a60c198627a03d34f9d36cdb95222d46d7bb319cf463c93f3e4d117cde31c95912ea988c85e7dcbefad359be3ec2f7c2
SSDeep 49152:1vee821/aQWl8P0lSk3aKA3Z+nl1s7dpb8oGdxTbTHHB72eh2NT:1vd821/aQWl8P0lSk3DA3Z+nfsc
TLSH 8BE55B1477F85E23E1ABE277E5B0445263F1F82EB363EB0B619166BE1C93B4048417A7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client
Full Name
Client
EntryPoint
System.Void 薜㗝辧잟큏ꑏ噖펡氭㑶ᖺᫎ롙뇔竩::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 薜㗝辧잟큏ꑏ噖펡氭㑶ᖺᫎ롙뇔竩::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 薜㗝辧잟큏ꑏ噖펡氭㑶ᖺᫎ롙뇔竩::潼鬊ꁙ铳뚏�耹餉斊ꜳꟇ舅퐫諓鶦ช�(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 薜㗝辧잟큏ꑏ噖펡氭㑶ᖺᫎ롙뇔竩::賷띋㨩輸肀ᄒ뚠讋옥㐞µ�Ⲅ疨娭夿箒谚蕢(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 兲伐殣倊꤁蜕�陔犋䓜삇ꢀ琻뿣充繊卧::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void 薜㗝辧잟큏ꑏ噖펡氭㑶ᖺᫎ롙뇔竩::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 薜㗝辧잟큏ꑏ噖펡氭㑶ᖺᫎ롙뇔竩::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 薜㗝辧잟큏ꑏ噖펡氭㑶ᖺᫎ롙뇔竩::潼鬊ꁙ铳뚏�耹餉斊ꜳꟇ舅퐫諓鶦ช�(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 薜㗝辧잟큏ꑏ噖펡氭㑶ᖺᫎ롙뇔竩::賷띋㨩輸肀ᄒ뚠讋옥㐞µ�Ⲅ疨娭夿箒谚蕢(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 兲伐殣倊꤁蜕�陔犋䓜삇ꢀ琻뿣充繊卧::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙