Suspicious
Suspect

93d3e455557f8b3cf1af9f8c020317e2

PE Executable
MD5: 93d3e455557f8b3cf1af9f8c020317e2
Size: 3.43 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 93d3e455557f8b3cf1af9f8c020317e2
Sha1 27da24185729764e435884cd2fc99a0b2ea041be
Sha256 befd43899d3fd6441ae166811caf6c71c5f28cded92b567562b5186d942e6cd2
Sha384 1eb2849787b47572d3cf87a0e6a52a6a009b8b400d9654aab11a8c7be1c7c886bba2053a7238442a462328eec912aa42
Sha512 a7c92753b30ebcfb34678e69a7ee650b3e02976ccfe78c4d46ccbad500f658819e8b5f3a1510cc24a26b1f9d7dd83e892ffdea57be0cfd0d066012ffae624393
SSDeep 49152:dvn+j2teai5mmP3lhsFQawoSgGsYRJ6WbR3LoGdMTHHB72eh2NT:dv+j2teai5mmP3lhsFhwoSgGsYRJ6Q
TLSH 53F5181C27F44E27E0BAE37795B8402657B2E85AB763974F21C1676938F3B4088C3667
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client
Full Name
Client
EntryPoint
System.Void 䁌샴䵌꽾ஏ黌ᣕ역쩽꠮᯹뽉翨ŗⰁℕ잁::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 䁌샴䵌꽾ஏ黌ᣕ역쩽꠮᯹뽉翨ŗⰁℕ잁::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 䁌샴䵌꽾ஏ黌ᣕ역쩽꠮᯹뽉翨ŗⰁℕ잁::꾣໒릎譐淝祽ꥎ뫲띯祐ⓤꍻ�興阎뚄疋(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 䁌샴䵌꽾ஏ黌ᣕ역쩽꠮᯹뽉翨ŗⰁℕ잁::觌煹ﻁ윎k橉翎�喫얰�隭ꌴ叆曁琌ፎ䣽⑰�(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 炿藦嶁セ�벇䧲뮵肫윲嶖瀃がસ㰶쵵ᖉ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void 䁌샴䵌꽾ஏ黌ᣕ역쩽꠮᯹뽉翨ŗⰁℕ잁::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 䁌샴䵌꽾ஏ黌ᣕ역쩽꠮᯹뽉翨ŗⰁℕ잁::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 䁌샴䵌꽾ஏ黌ᣕ역쩽꠮᯹뽉翨ŗⰁℕ잁::꾣໒릎譐淝祽ꥎ뫲띯祐ⓤꍻ�興阎뚄疋(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 䁌샴䵌꽾ஏ黌ᣕ역쩽꠮᯹뽉翨ŗⰁℕ잁::觌煹ﻁ윎k橉翎�喫얰�隭ꌴ叆曁琌ፎ䣽⑰�(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 炿藦嶁セ�벇䧲뮵肫윲嶖瀃がસ㰶쵵ᖉ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙