General

  • Target

    2024-06-19_90fa7689ebdca38d85f25cc6b6f72c47_icedid_quasar-rat_xrat

  • Size

    4.7MB

  • Sample

    240619-ge5qbazbnq

  • MD5

    90fa7689ebdca38d85f25cc6b6f72c47

  • SHA1

    34d27a5d2ced8d8bca9aa270a7a4c88e0eb4b588

  • SHA256

    8429096a142bd8a48c53449b37a09754e1b005b4a5e6f431364eb6fb766c3455

  • SHA512

    8ae9c7d7fadc20bc268a32d285bfd3cca042fa4400f24830c273724ee570c5b16becc0697939eec1837f6970404102e85172f831bc56b8eaa8d2d5572d3037bb

  • SSDEEP

    98304:S0Cnq7jXvr22SsaNYfdPBldt6+dBcjHtKRJ6BUIbzZgIbzZY:6QM7jGIH9K

Malware Config

Extracted

Family

quasar

Version

1.4.1

Botnet

Office04

C2

mx5.deitie.asia:4495

Mutex

ebbf737a-dddd-43dd-9b0a-74831302455d

Attributes
  • encryption_key

    F8516D89A1DFD78BD8FF575BBC3AE828B47FF0E1

  • install_name

    Client.exe

  • log_directory

    Logs

  • reconnect_delay

    3000

  • startup_key

    Quasar Client Startup

  • subdirectory

    SubDir

Targets

    • Target

      2024-06-19_90fa7689ebdca38d85f25cc6b6f72c47_icedid_quasar-rat_xrat

    • Size

      4.7MB

    • MD5

      90fa7689ebdca38d85f25cc6b6f72c47

    • SHA1

      34d27a5d2ced8d8bca9aa270a7a4c88e0eb4b588

    • SHA256

      8429096a142bd8a48c53449b37a09754e1b005b4a5e6f431364eb6fb766c3455

    • SHA512

      8ae9c7d7fadc20bc268a32d285bfd3cca042fa4400f24830c273724ee570c5b16becc0697939eec1837f6970404102e85172f831bc56b8eaa8d2d5572d3037bb

    • SSDEEP

      98304:S0Cnq7jXvr22SsaNYfdPBldt6+dBcjHtKRJ6BUIbzZgIbzZY:6QM7jGIH9K

    • Quasar RAT

      Quasar is an open source Remote Access Tool.

    • Quasar payload

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Drops startup file

    • Executes dropped EXE

    • Loads dropped DLL

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Persistence

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Privilege Escalation

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Discovery

Query Registry

2
T1012

System Information Discovery

2
T1082

Remote System Discovery

1
T1018

Tasks