Suspicious
Suspect

PE Executable
MD5: 9950cf752957adbe62bfd6d9b9d1fad0
Size: 3.34 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 9950cf752957adbe62bfd6d9b9d1fad0
Sha1 fabe2e7090814c6b6870a881f7d55126926fa0c9
Sha256 2aeef6545efb7b271af6e284b6128a3d7031cf2bcafc782d7912d312bedbba01
Sha384 e1d7a792cf1bb458b35ed6bc0f3771f4862cebfcdc915d710e0f67f4c1011f85b0f5bdb63281bc9e619ed0e64eb8599a
Sha512 5393f7e03ea236febdebcff69e11f4148efbdd00df9c08a7553ba485afdc95316dcc13bf223ad94a4ed9152c1caa057302934ba974b721815c7772ed1c57f9a7
SSDeep 49152:fv14U2FwaRoY/PVl5cy8TzdnmeOPxNESEgk/iBLoGdWTHHB72eh2NT:fvaU2FwaRoY/PVl5cyAzdnme2xnR
TLSH 4DF53A143BF85F22E1BBE27395B0041667F1ED2AB3A3EB1B2151677E1C53B4058427AB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client
Full Name
Client
EntryPoint
System.Void 림Ɦ윯ꠅ㇦ז‚ꕺ␹嶿਽ꓸف⥍ꭟﵥӋ::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 림Ɦ윯ꠅ㇦ז‚ꕺ␹嶿਽ꓸف⥍ꭟﵥӋ::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 림Ɦ윯ꠅ㇦ז‚ꕺ␹嶿਽ꓸف⥍ꭟﵥӋ::➸飣࣊䂑䜧ꏄ醀ⰷ둞畣곉렍诟冚䙓ퟳ傰(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 림Ɦ윯ꠅ㇦ז‚ꕺ␹嶿਽ꓸف⥍ꭟﵥӋ::㕍祓毜ࡏ蔥伂闀據핍Ⅎ㐔狉牠쯭⼽긤᯿ᝲ(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 㫲樈䔽嬸뢟叼휾쿴絑겍喛爚蚫챕擊፟::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void 림Ɦ윯ꠅ㇦ז‚ꕺ␹嶿਽ꓸف⥍ꭟﵥӋ::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 림Ɦ윯ꠅ㇦ז‚ꕺ␹嶿਽ꓸف⥍ꭟﵥӋ::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 림Ɦ윯ꠅ㇦ז‚ꕺ␹嶿਽ꓸف⥍ꭟﵥӋ::➸飣࣊䂑䜧ꏄ醀ⰷ둞畣곉렍诟冚䙓ퟳ傰(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 림Ɦ윯ꠅ㇦ז‚ꕺ␹嶿਽ꓸف⥍ꭟﵥӋ::㕍祓毜ࡏ蔥伂闀據핍Ⅎ㐔狉牠쯭⼽긤᯿ᝲ(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 㫲樈䔽嬸뢟叼휾쿴絑겍喛爚蚫챕擊፟::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙