Suspicious
Suspect

PE Executable
MD5: f9315ffac9bb0d8359d0a2f1ac52302b
Size: 3.27 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 f9315ffac9bb0d8359d0a2f1ac52302b
Sha1 350c0c5e239e85becd1484ffa97edd342b460de0
Sha256 13e7bfcc010ebce3f3a04fdcfda360dbce0167ed4c7a53dc06f68a93064aa424
Sha384 01407ba19e0911c5e6af1fad07af535b993de96d25eb55910db60b91a483a9358413efade87e36aa312573ca763ac561
Sha512 7bf72be53ff82e78cb2aac0ead9c0d3be3974cb70801ba33b44071e285d37b2ad08fb846035ba50a11a34675eb0ed91607117aa02dc89527b9c8632796f2009c
SSDeep 49152:cvFL82kyaNnwxPlllSWxc9LpQXqG1QqUartZoGdUTHHB72eh2NT:cv182kyaNnwxPlllSWa9LpQX3qqZ
TLSH B0E54A1437F85E23E1ABE373D5B0041767F1F82AB363EB0B6191677A5C53B508842AA7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client
Full Name
Client
EntryPoint
System.Void כֿ倥␼뒌�黛舭陋㡅渮施ᣉ灁ỳ쮞㓯꾕斐::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void כֿ倥␼뒌�黛舭陋㡅渮施ᣉ灁ỳ쮞㓯꾕斐::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void כֿ倥␼뒌�黛舭陋㡅渮施ᣉ灁ỳ쮞㓯꾕斐::鎐쟥獠嫓�鸏ဖ衿ﷆ紦聧簏ﲵ瀀ꐦ䤄ﺸ(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void כֿ倥␼뒌�黛舭陋㡅渮施ᣉ灁ỳ쮞㓯꾕斐::岤䦷짿遗畟家↵궣ჯケ寿ƣ蔉Ꝉ穌駥⼞ꋒ(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void ␛ꉡ塹⧁൜樾︞뺡▄꾘䶂㩽崓㲸ᢰ떬쉃젱::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void כֿ倥␼뒌�黛舭陋㡅渮施ᣉ灁ỳ쮞㓯꾕斐::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void כֿ倥␼뒌�黛舭陋㡅渮施ᣉ灁ỳ쮞㓯꾕斐::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void כֿ倥␼뒌�黛舭陋㡅渮施ᣉ灁ỳ쮞㓯꾕斐::鎐쟥獠嫓�鸏ဖ衿ﷆ紦聧簏ﲵ瀀ꐦ䤄ﺸ(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void כֿ倥␼뒌�黛舭陋㡅渮施ᣉ灁ỳ쮞㓯꾕斐::岤䦷짿遗畟家↵궣ჯケ寿ƣ蔉Ꝉ穌駥⼞ꋒ(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void ␛ꉡ塹⧁൜樾︞뺡▄꾘䶂㩽崓㲸ᢰ떬쉃젱::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙