General

  • Target

    Tiktok-Share-Bot-By-Denmark.zip

  • Size

    11.6MB

  • MD5

    54bbebf31363300459fd1660bf5493b7

  • SHA1

    c8ff555abf4a179a9bcb32c0e2d4fb502061bbbe

  • SHA256

    ef7a777d354433cc1398552311446bbc0be13e34407ca6fd7a67e4c750e76183

  • SHA512

    faeacb7860aec90cee53cb975d98bb6a1f01392c2a4914c27e6c259b05728def6352a9d2c82ff01d68056bd50df17a5b2cad7590725a127131844b0458a1b676

  • SSDEEP

    196608:A7gyk60n8baTVsxzDJmXCoy86Q4/+VfB0g5hNF1SqAk3bfQzMzh:A7g/8GZsuSoy86QktOSqLM2h

Score
10/10

Malware Config

Extracted

Family

quasar

Attributes
  • reconnect_delay

    3000

Signatures

  • Contains code to disable Windows Defender 2 IoCs

    A .NET executable tasked with disabling Windows Defender capabilities such as realtime monitoring, blocking at first seen, etc.

  • Quasar family
  • Quasar payload 2 IoCs
  • SectopRAT payload 2 IoCs
  • Sectoprat family
  • Unsigned PE 4 IoCs

    Checks for missing Authenticode signature.

Files

  • Tiktok-Share-Bot-By-Denmark.zip
    .zip
  • Read.txt
  • Tiktok Share Bot byDenmark.exe
    .exe windows:6 windows x86 arch:x86

    a283dafca83c0a2a8ece9859011b15c6


    Headers

    Imports

    Sections

  • data32.bin
    .exe windows:6 windows x86 arch:x86

    0392634acac147c03d108c2d046e7996


    Headers

    Imports

    Sections

  • libGLESV2.lib
    .exe windows:4 windows x86 arch:x86

    f34d5f2d4577ed6d9ceec516c1f5a744


    Headers

    Imports

    Sections

  • libcef.bin
    .exe windows:6 windows x86 arch:x86

    b66f87cf58494faf62e606c7906acafe


    Headers

    Imports

    Sections