Suspicious
Suspect

PE Executable
MD5: 621ba2c4870126cee3e1d198911753b7
Size: 3.27 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 621ba2c4870126cee3e1d198911753b7
Sha1 5b4ed2899cfa3cb433a7ed672c436c3573c1e5c8
Sha256 28852b784a3ace6554544ea14795a3f1cd1d37228bfcfe2eebe09dc667a1978d
Sha384 e6e48a45335a77103c2169a688177033313871070daa5bab18429293a2dfe7a685f7620d01926d4e973e04098e2c3758
Sha512 8069a46c1daf93d584d4f4fe63ee8360847da967927a94e0f66a20da628bef2f4abfe70315e341d22b9806581453b6e0fcfb3ee5755b3705ea8ff9b4697ee70f
SSDeep 49152:yvSI22SsaNYfdPBldt698dBcjHdbDobRcLoGdZYUTHHB72eh2NT:yv/22SsaNYfdPBldt6+dBcjHdbDLp
TLSH CAE55B143BF85F27E1BBE27795B0041267F0FC1AB3A3EB0B658167791C93B5098426A7
PeID
.NET executableMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client
Full Name
Client
EntryPoint
System.Void 㯶Ⓔ፟䎦੒Ლ쳳莟╝䨑빙岚㪜腣٦䘢彪࿀::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 㯶Ⓔ፟䎦੒Ლ쳳莟╝䨑빙岚㪜腣٦䘢彪࿀::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 㯶Ⓔ፟䎦੒Ლ쳳莟╝䨑빙岚㪜腣٦䘢彪࿀::ⵓ桼ޚ磬넆獔⯱근㧈䳚㬩땭곎㤼ጟ繊㡌(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 㯶Ⓔ፟䎦੒Ლ쳳莟╝䨑빙岚㪜腣٦䘢彪࿀::庝ퟶ̩୑턋沬䨈㯷㽆㡢�ﳟ竜澳蔺뮈줂댔鞺(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 湀㈉鶋⣥睁㰊䞌귃➏ᜯ꼹탴볕�梱敛쬣::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void 㯶Ⓔ፟䎦੒Ლ쳳莟╝䨑빙岚㪜腣٦䘢彪࿀::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 㯶Ⓔ፟䎦੒Ლ쳳莟╝䨑빙岚㪜腣٦䘢彪࿀::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 㯶Ⓔ፟䎦੒Ლ쳳莟╝䨑빙岚㪜腣٦䘢彪࿀::ⵓ桼ޚ磬넆獔⯱근㧈䳚㬩땭곎㤼ጟ繊㡌(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 㯶Ⓔ፟䎦੒Ლ쳳莟╝䨑빙岚㪜腣٦䘢彪࿀::庝ퟶ̩୑턋沬䨈㯷㽆㡢�ﳟ竜澳蔺뮈줂댔鞺(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 湀㈉鶋⣥睁㰊䞌귃➏ᜯ꼹탴볕�梱敛쬣::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙