General

  • Target

    Oski Cracked.exe

  • Size

    4.5MB

  • MD5

    a52baa5b64635eec7c7b888bff016aac

  • SHA1

    a86b895b483df3c657553f498ebcd9c97b89415f

  • SHA256

    cd986b32c220cc04c9feb5e42a393fb34efc884d176e6d8d266e54ac4840cfa3

  • SHA512

    bed140ed03ed4b5da82edf1139eced7c84a56fe75f5a8926002414ed0b8f25fbb6cbf9e3111ff6d9b5d942382be331a674f17cf10b2150f171f32276ad4b3980

  • SSDEEP

    98304:iJCbuSMburCaMZh0yEKj+WRvrY1dcZ048HV/bFy8jJ7APB:8mMbuQZlFY7KsZPNA

Score
10/10

Malware Config

Extracted

Family

quasar

Attributes
  • reconnect_delay

    3000

Signatures

  • Contains code to disable Windows Defender 1 IoCs

    A .NET executable tasked with disabling Windows Defender capabilities such as realtime monitoring, blocking at first seen, etc.

  • Quasar family
  • Quasar payload 1 IoCs
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • Oski Cracked.exe
    .exe windows:4 windows x86 arch:x86

    f34d5f2d4577ed6d9ceec516c1f5a744


    Headers

    Imports

    Sections