Suspicious
Suspect

PE Executable
MD5: 8fabbf87b27577939013d86df2604a91
Size: 3.27 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 8fabbf87b27577939013d86df2604a91
Sha1 c0fc38b04b779ce02fdab792a43460348f816982
Sha256 af9c255e0ddd0fc5952840efca25a1e103c3e25d5d6cb1a4361dbd2d61c512cb
Sha384 30a0a12b86d7ae32551fb532adc10efbc92cf3783df2288e3d032a724bed610cae93143126a6205bfaa636ce6527c075
Sha512 5ed4668386b103396889ef7fe94cd089a08ee00489ccfef2883e4c4d5c2b6a91720a205e4e2819e07a283ef6346a98ece3d507e239482fff7e9bc9c729d72fad
SSDeep 49152:dvDlL26AaNeWgPhlmVqvMQ7XSKBSRJ65bR3LoGdSRTHHB72eh2NT:dv5L26AaNeWgPhlmVqkQ7XSKBSRJ67i
TLSH B0E56B143BF85E27E1BBE277E5B0041267F0FC1AB363EB0B6581677A1C53B5098426A7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client
Full Name
Client
EntryPoint
System.Void 窅应墖햓䖔넇ᄅ⛻랢﬩俬낛콎⌴㶬훣㢺::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 窅应墖햓䖔넇ᄅ⛻랢﬩俬낛콎⌴㶬훣㢺::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 窅应墖햓䖔넇ᄅ⛻랢﬩俬낛콎⌴㶬훣㢺::崵꧔ຶ湾べ๥뮦뎢૧ᠸ鸅겑Ⳝֈ㉶膵ꧏ캡쾵(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 窅应墖햓䖔넇ᄅ⛻랢﬩俬낛콎⌴㶬훣㢺::둬斏꛶ڽ긎ꔐ硔䋂礽礪鼑婍᪥⩋㹞燷搹峺礽(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 䡪㗒踰숡詵ɰ쩏鎛鞯紘�䐥荀䍉ꙋ蠵Ɤ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void 窅应墖햓䖔넇ᄅ⛻랢﬩俬낛콎⌴㶬훣㢺::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 窅应墖햓䖔넇ᄅ⛻랢﬩俬낛콎⌴㶬훣㢺::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 窅应墖햓䖔넇ᄅ⛻랢﬩俬낛콎⌴㶬훣㢺::崵꧔ຶ湾べ๥뮦뎢૧ᠸ鸅겑Ⳝֈ㉶膵ꧏ캡쾵(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 窅应墖햓䖔넇ᄅ⛻랢﬩俬낛콎⌴㶬훣㢺::둬斏꛶ڽ긎ꔐ硔䋂礽礪鼑婍᪥⩋㹞燷搹峺礽(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 䡪㗒踰숡詵ɰ쩏鎛鞯紘�䐥荀䍉ꙋ蠵Ɤ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙