Suspicious
Suspect

4e8f5080d5d689a6e2fabe926f888376

PE Executable
MD5: 4e8f5080d5d689a6e2fabe926f888376
Size: 3.27 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 4e8f5080d5d689a6e2fabe926f888376
Sha1 93c72f68b01001b247950d0cc223d26b7ceae1fc
Sha256 e2839ed50fc0ac6a3a4c3e62bb8adce09bf7bcd7a74eefc81b25bbfd95422a75
Sha384 2998fe0345b437243faf71d18415430a80ed2770cb48cb182e5c3ff0ca1d7f92898cfd83468494ebe14c60e5bd8a52e9
Sha512 6717ee336ae83d2865b06fefbaf731140014ecc9a0f47185e19893430b1293b818b2de4aa314d8e4fbb6cc260049b18d633928b38ce3eae9c282256b5540dda0
SSDeep 49152:avPI22SsaNYfdPBldt698dBcjH0W9raMfYLoGdBTHHB72eh2NT:avA22SsaNYfdPBldt6+dBcjH0W9rA
TLSH 0AE55A143BF85E63E16AD773DAB0501263F1FC2AF363EB1B6191667E1C53B4058026AB
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
Name Value
Module Name
Client
Full Name
Client
EntryPoint
System.Void 齰ﭩ�䏸縺Ⴜ⭋尶ꬶ￈鋺⛸윞뗍놝悲ꔅ::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 齰ﭩ�䏸縺Ⴜ⭋尶ꬶ￈鋺⛸윞뗍놝悲ꔅ::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 齰ﭩ�䏸縺Ⴜ⭋尶ꬶ￈鋺⛸윞뗍놝悲ꔅ::꣘ꖙ㬕⎗穎飨鶩瘶鐴棲ᔉ竪붹刴❄뫆㾈(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 齰ﭩ�䏸縺Ⴜ⭋尶ꬶ￈鋺⛸윞뗍놝悲ꔅ::ソⳭ�颫㿦惾蒾놤긺啸输䩕궄ᗬ叔孵�࠳⥛(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 僇ᩓɻ뮫ﯱ䜵疃죅⭬੼郃ビʛ樼驽礜㈰ᡙṈ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void 齰ﭩ�䏸縺Ⴜ⭋尶ꬶ￈鋺⛸윞뗍놝悲ꔅ::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 齰ﭩ�䏸縺Ⴜ⭋尶ꬶ￈鋺⛸윞뗍놝悲ꔅ::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 齰ﭩ�䏸縺Ⴜ⭋尶ꬶ￈鋺⛸윞뗍놝悲ꔅ::꣘ꖙ㬕⎗穎飨鶩瘶鐴棲ᔉ竪붹刴❄뫆㾈(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 齰ﭩ�䏸縺Ⴜ⭋尶ꬶ￈鋺⛸윞뗍놝悲ꔅ::ソⳭ�颫㿦惾蒾놤긺啸输䩕궄ᗬ叔孵�࠳⥛(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 僇ᩓɻ뮫ﯱ䜵疃죅⭬੼郃ビʛ樼驽礜㈰ᡙṈ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙