Suspicious
Suspect

PE Executable
MD5: 69642129bb04ee0004c255eda28ac9b1
Size: 3.27 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 69642129bb04ee0004c255eda28ac9b1
Sha1 edc937eebf3fbcdc2e8d1787bde59630c5544dc9
Sha256 44b82ef3b8a911c429a6c62b32af7523eefbd7463b261a8511c1af5bb66845bf
Sha384 918e49ff365982ee961b8ea0e25a59ceb528514ec5ed0d7064a43116701bf50c53b40f1e782d72f100f7c59b728fc8e9
Sha512 e2d257138061d8b6b940530bfa503dfff82ef9a48409a6e8042c231111e3898f92b3850d83f97827f40148f411ee414ee81c0d70a6454c124de77cedcb5c7c68
SSDeep 49152:3vNI22SsaNYfdPBldt698dBcjH//x3darKLoGdgTHHB72eh2NT:3vG22SsaNYfdPBldt6+dBcjHh3t
TLSH 25E54A1037F85E23E1ABE37395B0041767F1FC2AB3A3EB0B6191677A5C53B504942AA7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
Name Value
Module Name
Client
Full Name
Client
EntryPoint
System.Void Ꟈ쿾�갳腲꺂葕夫ꚮᔨ厑�߾㼪톋Ԩ庌걤::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void Ꟈ쿾�갳腲꺂葕夫ꚮᔨ厑�߾㼪톋Ԩ庌걤::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void Ꟈ쿾�갳腲꺂葕夫ꚮᔨ厑�߾㼪톋Ԩ庌걤::ႋ듄ᘺ玺멂臀ᘄ೺夘雅㌢췥潜疉럺淼㟍醁(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void Ꟈ쿾�갳腲꺂葕夫ꚮᔨ厑�߾㼪톋Ԩ庌걤::摺襇䪳餶�擪᎕䡛徶奱觕㨧厬㦇豦봓좮(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 뇸ﯨ㊁圪繴覂ᖯ꟭訣ꘄ茕䲉萉ख़͵ㄴᆈ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void Ꟈ쿾�갳腲꺂葕夫ꚮᔨ厑�߾㼪톋Ԩ庌걤::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void Ꟈ쿾�갳腲꺂葕夫ꚮᔨ厑�߾㼪톋Ԩ庌걤::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void Ꟈ쿾�갳腲꺂葕夫ꚮᔨ厑�߾㼪톋Ԩ庌걤::ႋ듄ᘺ玺멂臀ᘄ೺夘雅㌢췥潜疉럺淼㟍醁(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void Ꟈ쿾�갳腲꺂葕夫ꚮᔨ厑�߾㼪톋Ԩ庌걤::摺襇䪳餶�擪᎕䡛徶奱觕㨧厬㦇豦봓좮(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 뇸ﯨ㊁圪繴覂ᖯ꟭訣ꘄ茕䲉萉ख़͵ㄴᆈ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙