Suspicious
Suspect

PE Executable
MD5: c3a0fc64e82ec085618b2d5d0d2cdb01
Size: 3.27 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 c3a0fc64e82ec085618b2d5d0d2cdb01
Sha1 902de2495ff16c33de5c5c22baa461e813b936d4
Sha256 49c0cc5f278c0e3c372a9ef3029697cd36da5cf25ff2f817bbf4256dd3f1f4df
Sha384 9f29589fa95163ad2444c7b68ded207cafb600368aa02de691ad87974c29963817aeef44042a2fcb15f9acfd3550c2cf
Sha512 4e073ac9a5475c4cfea0671da90d01e419610c88c3f0754ccf03bef4f298de0aa88ec067a8a324442cd7d5757fe16363949e169ca98c6e5eb97484314f80bbbe
SSDeep 49152:mvTlL26AaNeWgPhlmVqvMQ7XSKMgRDyPkCALoGJHsSTATHHB72eh2NT:mvJL26AaNeWgPhlmVqkQ7XSKRRDywz
TLSH 40E5491477F85E32E1AAD37295F0541367F0FC2EF3A3EB0B6591667A1C93B4088426A7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client
Full Name
Client
EntryPoint
System.Void 弓諭䢇á䐋ᯪ�괨姨辢✌䡹ꗲ훩ㅅ퇈ꤳ::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 弓諭䢇á䐋ᯪ�괨姨辢✌䡹ꗲ훩ㅅ퇈ꤳ::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 弓諭䢇á䐋ᯪ�괨姨辢✌䡹ꗲ훩ㅅ퇈ꤳ::坧扺쀗燆寊쳏帠l姶뗗荨�㸲鵏浄麆뽼⪼服(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 弓諭䢇á䐋ᯪ�괨姨辢✌䡹ꗲ훩ㅅ퇈ꤳ::ⵋԽ엵፜苍ꞡ䮼⠳虆釈䚦鍗墼ꜝᘉ珀ꍩ컺(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 䈅캌쮅䈐뵈踮ड़ꭝ鰢⍄䫃떺ᄀ飾űⲴθㄭ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void 弓諭䢇á䐋ᯪ�괨姨辢✌䡹ꗲ훩ㅅ퇈ꤳ::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 弓諭䢇á䐋ᯪ�괨姨辢✌䡹ꗲ훩ㅅ퇈ꤳ::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 弓諭䢇á䐋ᯪ�괨姨辢✌䡹ꗲ훩ㅅ퇈ꤳ::坧扺쀗燆寊쳏帠l姶뗗荨�㸲鵏浄麆뽼⪼服(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 弓諭䢇á䐋ᯪ�괨姨辢✌䡹ꗲ훩ㅅ퇈ꤳ::ⵋԽ엵፜苍ꞡ䮼⠳虆釈䚦鍗墼ꜝᘉ珀ꍩ컺(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 䈅캌쮅䈐뵈踮ड़ꭝ鰢⍄䫃떺ᄀ飾űⲴθㄭ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙