Suspicious
Suspect

PE Executable
MD5: 9521c73f364f9a66444ce7065e965e9b
Size: 3.27 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 9521c73f364f9a66444ce7065e965e9b
Sha1 3a4c5dcff86c4f79ec4478d4fba577dbadbb1d25
Sha256 13550a5e7639e691d674db4efef9a4cb352c9a201d154de077f313861bc3cbf6
Sha384 385c07c0b3653f8a688d4de1d66d6dea09748b085cce445156d72d93836189803124735cea5eb83906ae5c5d6d59f4c4
Sha512 9b39965f62f7da372c8498e47b2d31911d475c900e68dda90fb5721ba22403ecd106add29b141d1472e45ae06e5c7ceefca9591fed938d46f7d27353bccf5c47
SSDeep 49152:rvnI22SsaNYfdPBldt698dBcjHBCu1JVLoGd/THHB72eh2NT:rvI22SsaNYfdPBldt6+dBcjHBC4
TLSH EDE54A1437F85E23E1BBE273D5B0041267F1EC2AB3A3FB4B6191677A1C53B505841AAB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
Name Value
Module Name
Client
Full Name
Client
EntryPoint
System.Void 镒諙鷐耏碰〲纹䷯㷥㭶抟躯焫庛습闊髚젯詍::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 镒諙鷐耏碰〲纹䷯㷥㭶抟躯焫庛습闊髚젯詍::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 镒諙鷐耏碰〲纹䷯㷥㭶抟躯焫庛습闊髚젯詍::ネ嚚ꁰ�弣튗䆀䲊ʀ쬟棾ゅ뇉䡈ꅳ䢃ᄄ葽쳻(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 镒諙鷐耏碰〲纹䷯㷥㭶抟躯焫庛습闊髚젯詍::ҿ驾슄領썡젊‰ᮼꊔ焃뭑阞朾覣쩄溫潁ᐒ옽(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 帗룱쁙㉡␍�ꌎ␷͚赸䲹田럑涔빴ꖝୃ皇::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void 镒諙鷐耏碰〲纹䷯㷥㭶抟躯焫庛습闊髚젯詍::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 镒諙鷐耏碰〲纹䷯㷥㭶抟躯焫庛습闊髚젯詍::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 镒諙鷐耏碰〲纹䷯㷥㭶抟躯焫庛습闊髚젯詍::ネ嚚ꁰ�弣튗䆀䲊ʀ쬟棾ゅ뇉䡈ꅳ䢃ᄄ葽쳻(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 镒諙鷐耏碰〲纹䷯㷥㭶抟躯焫庛습闊髚젯詍::ҿ驾슄領썡젊‰ᮼꊔ焃뭑阞朾覣쩄溫潁ᐒ옽(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 帗룱쁙㉡␍�ꌎ␷͚赸䲹田럑涔빴ꖝୃ皇::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙