Suspicious
Suspect

PE Executable
MD5: e8113856b4f6fa34f18f0682e9ca6dfd
Size: 3.27 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 e8113856b4f6fa34f18f0682e9ca6dfd
Sha1 30005649c7c6b4b978ea805b33a77d84ec13a43b
Sha256 65348e42e2663898e3c87af9b103e83567dc8045bdd8a4a95f430b4e99f032b3
Sha384 fa38ee203eae3db4b17f2ffb87f99c4d6542081e0f70cfd1c9c6880953bef43f4554778c1930acae537ef01cb7e3eda4
Sha512 4a6ba2da5bf75f03038cb59434dd483a96307e755ac6861f75704bc80fb9a6f14c4b4343295035126aaa4c7bd18cc8287a073166e01c127887a6930a37e97d97
SSDeep 49152:2vkt62XlaSFNWPjljiFa2RoUYI7lqCOoGdLpTHHB72eh2NT:2v462XlaSFNWPjljiFXRoUYI7lqH
TLSH 6CE56A103BF85E33E16BD6B3D5B0502267F1F82AF363EB5B2181667A1C53B6148427A7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client
Full Name
Client
EntryPoint
System.Void 㺫ό燳ߘष⥤Ⱦ㄄뷺ଟ甭䗅ᦡ굳뭞瀇ꗠ::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 㺫ό燳ߘष⥤Ⱦ㄄뷺ଟ甭䗅ᦡ굳뭞瀇ꗠ::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 㺫ό燳ߘष⥤Ⱦ㄄뷺ଟ甭䗅ᦡ굳뭞瀇ꗠ::伤仕ါⰳ㫃攝�琱굈獫쬊떄巂丏䴀໠쮿⎣馪(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 㺫ό燳ߘष⥤Ⱦ㄄뷺ଟ甭䗅ᦡ굳뭞瀇ꗠ::ް償糰첂ፚ菶柠殰춁㾢驨ᔌ聃䌔娲㜝폋젴铮羠(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 늾嚴译ꗨ煦ꍺࡓ堒儷鈽筨ⵌ輻녋හ퐤튠ꤨ钑ㆍ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void 㺫ό燳ߘष⥤Ⱦ㄄뷺ଟ甭䗅ᦡ굳뭞瀇ꗠ::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 㺫ό燳ߘष⥤Ⱦ㄄뷺ଟ甭䗅ᦡ굳뭞瀇ꗠ::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 㺫ό燳ߘष⥤Ⱦ㄄뷺ଟ甭䗅ᦡ굳뭞瀇ꗠ::伤仕ါⰳ㫃攝�琱굈獫쬊떄巂丏䴀໠쮿⎣馪(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 㺫ό燳ߘष⥤Ⱦ㄄뷺ଟ甭䗅ᦡ굳뭞瀇ꗠ::ް償糰첂ፚ菶柠殰춁㾢驨ᔌ聃䌔娲㜝폋젴铮羠(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 늾嚴译ꗨ煦ꍺࡓ堒儷鈽筨ⵌ輻녋හ퐤튠ꤨ钑ㆍ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙