Malicious
Malicious

dfd799bb5c65ad4e3f237b304d726aff

PE Executable
MD5: dfd799bb5c65ad4e3f237b304d726aff
Size: 514.05 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 dfd799bb5c65ad4e3f237b304d726aff
Sha1 43d93a3933061a00a4d8dbf41fae87bb55923dc7
Sha256 fda825f6ddd6738d57b8a7c16b793d7580ff3bb0427b6b5412d4b82c8bae3145
Sha384 c6dbb01fc52ca1b5902e4939cfb236922e258918f1c4ef8e379b67922d566a748debb08c09bd840c390d38e60081686e
Sha512 1c7304db7fa8620718c9c78cd56f97d2a62c4a0ed9de381aee8b5dbac421fa093dd89bbb0328ae72cae4558c7ad95921a5f8cc38fb87f6b101cdee742c951d25
SSDeep 6144:xTEgdc0YRX7IxUpGREWwpdPUxlgeDrR178tclcE2xb8FM+u5+Uv6NcTR3y:xTEgdfYyxUjj4DhmeRIvvIcdy
TLSH 5FB46D4067F88527E1AE57BAE87104219BF5F807B26BEF4F4A40B2F92C667069D40773
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
Config. Field Value
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Key 3AC1ABhuhuhuhuhuhuhuhuhuhuhu
Version 1huhuhuhu
Port centehuhuhuhuhuhuhu
Host centehuhuhuhuhuhuhu
ReconnectDelay 1huhuhuhu
SubDirectory Suhuhuhuhu
InstallName Serhuhuhuhu
Install 1huhuhuhu
Startup 1huhuhuhu
Mutex d0a56dhuhuhuhuhuhuhuhuhuhuhu
StartupKey Windhuhuhuhuhuhuhu
HideFile 1huhuhuhu
EnableLogger 1huhuhuhu
Tag Sehuhuhuhu
LogDirectory Lhuhuhuhu
ServerSignature XjaNPthuhuhuhuhuhuhuhuhuhuhu
ServerCertificate MIIE9Dhuhuhuhuhuhuhuhuhuhuhu
HideLogDirectory 1huhuhuhu
HideLogSubdirectory 1huhuhuhu
UnattendedMod 1huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client
Full Name
Client
EntryPoint
System.Void 祛㶕਋ꉄ㟧鲥鉉ꡧ逥◫줼橮⛴渽䯠鞫::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
1552
Main Method
System.Void 祛㶕਋ꉄ㟧鲥鉉ꡧ逥◫줼橮⛴渽䯠鞫::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 祛㶕਋ꉄ㟧鲥鉉ꡧ逥◫줼橮⛴渽䯠鞫::拨톐왏경ꕭ얡�ꈸ첲ꦤᜓᢸ똱瞏省뱹䓑沜鉥쨖(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 祛㶕਋ꉄ㟧鲥鉉ꡧ逥◫줼橮⛴渽䯠鞫::㘳ඕ푶ῠ૜쩣䚪팽್ਲ਼鰊댓☞䫴遭(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void �à璷퀰屎᪤쁖᧞瘹ᢥ了댚颱ݩ맹ક埶躟篼::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void 祛㶕਋ꉄ㟧鲥鉉ꡧ逥◫줼橮⛴渽䯠鞫::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
1552
Main Method
System.Void 祛㶕਋ꉄ㟧鲥鉉ꡧ逥◫줼橮⛴渽䯠鞫::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 祛㶕਋ꉄ㟧鲥鉉ꡧ逥◫줼橮⛴渽䯠鞫::拨톐왏경ꕭ얡�ꈸ첲ꦤᜓᢸ똱瞏省뱹䓑沜鉥쨖(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 祛㶕਋ꉄ㟧鲥鉉ꡧ逥◫줼橮⛴渽䯠鞫::㘳ඕ푶ῠ૜쩣䚪팽್ਲ਼鰊댓☞䫴遭(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void �à璷퀰屎᪤쁖᧞瘹ᢥ了댚颱ݩ맹ક埶躟篼::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
CnC CNCmalicious
centehuhuhuhuhuhuhu
Port PORTmalicious
centehuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
Config. Field Value
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Key 3AC1ABhuhuhuhuhuhuhuhuhuhuhu
Version 1huhuhuhu
Port centehuhuhuhuhuhuhu
Host centehuhuhuhuhuhuhu
ReconnectDelay 1huhuhuhu
SubDirectory Suhuhuhuhu
InstallName Serhuhuhuhu
Install 1huhuhuhu
Startup 1huhuhuhu
Mutex d0a56dhuhuhuhuhuhuhuhuhuhuhu
StartupKey Windhuhuhuhuhuhuhu
HideFile 1huhuhuhu
EnableLogger 1huhuhuhu
Tag Sehuhuhuhu
LogDirectory Lhuhuhuhu
ServerSignature XjaNPthuhuhuhuhuhuhuhuhuhuhu
ServerCertificate MIIE9Dhuhuhuhuhuhuhuhuhuhuhu
HideLogDirectory 1huhuhuhu
HideLogSubdirectory 1huhuhuhu
UnattendedMod 1huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
CnC CNCmalicious
centehuhuhuhuhuhuhu
dfd799bb5c65ad4e3f237b304d726aff
Port PORTmalicious
centehuhuhuhuhuhuhu
dfd799bb5c65ad4e3f237b304d726aff
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙