Suspicious
Suspect

PE Executable
MD5: c987235f41fca560300f5d69e4085058
Size: 3.27 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 c987235f41fca560300f5d69e4085058
Sha1 9ef07f3eb12679fb42d704e0c99a7f060f6993a8
Sha256 028da5b0071980940242531e9192ebbd4e1776bc1de65a72f8adb9d56771603b
Sha384 426d610ab184d5b387541ed906d86c7a423d52655700492433a32a65c72b6cac7c248d9750f7338c75c76d8e69f39dd7
Sha512 04e2ab57361de15cf2c42119c7ad79d20152e085d4436675c086540c41b9ed3d40775d3acf3fc2a8203e9cf277af2fc55b7c977de57c7e8f0daa2d79dd138151
SSDeep 49152:rv2I22SsaNYfdPBldt698dBcjHfXYZ1JrhoGdTTHHB72eh2NT:rvb22SsaNYfdPBldt6+dBcjHfXYr
TLSH 3DE54A1437F85E23E1BBE273D5B0041267F0EC2AB3A3FB5B6191677A1C53B505841AAB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client
Full Name
Client
EntryPoint
System.Void ↲筛�ᘴ匲⑓뜷ሑ㛈㬬勌쿾㧐썎䟶::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void ↲筛�ᘴ匲⑓뜷ሑ㛈㬬勌쿾㧐썎䟶::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void ↲筛�ᘴ匲⑓뜷ሑ㛈㬬勌쿾㧐썎䟶::繲駺Ͽ뾗ꅨ垈릅擳▇⃐좭썙폟㤣ꁀ㰿(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void ↲筛�ᘴ匲⑓뜷ሑ㛈㬬勌쿾㧐썎䟶::ፁ戕᮹湝ᓻ㤶괥�活ᇎܿ䞋ስ阳慸䩏䃱(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 췿欷䵇㚶褖ມ蘼閾샤ǚ⤦兦�3䚈企$裂ꬅ㉞::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void ↲筛�ᘴ匲⑓뜷ሑ㛈㬬勌쿾㧐썎䟶::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void ↲筛�ᘴ匲⑓뜷ሑ㛈㬬勌쿾㧐썎䟶::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void ↲筛�ᘴ匲⑓뜷ሑ㛈㬬勌쿾㧐썎䟶::繲駺Ͽ뾗ꅨ垈릅擳▇⃐좭썙폟㤣ꁀ㰿(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void ↲筛�ᘴ匲⑓뜷ሑ㛈㬬勌쿾㧐썎䟶::ፁ戕᮹湝ᓻ㤶괥�活ᇎܿ䞋ስ阳慸䩏䃱(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 췿欷䵇㚶褖ມ蘼閾샤ǚ⤦兦�3䚈企$裂ꬅ㉞::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙