General

  • Target

    164e19d48c8d3ed423d4d4c68dff47899f375b6ef4f2a27005562e16b3a8d33f.exe

  • Size

    3.1MB

  • Sample

    240619-sj14gaxclr

  • MD5

    1b27e622f4edbbdd8fc93a0d1c129607

  • SHA1

    3e7b42dd10c01f632f158cc96701f6ba49ebec48

  • SHA256

    164e19d48c8d3ed423d4d4c68dff47899f375b6ef4f2a27005562e16b3a8d33f

  • SHA512

    bd6d609019f06649db920244a91ef5a2f105ea81055cdd53df72e737e1aae75b340060f45cb56383d201c154591a0a297fd69e1d09c5239b96ea5765a823ef5c

  • SSDEEP

    49152:kvHI22SsaNYfdPBldt698dBcjHn30LdBhJo2d/UTHHB72eh2NT:kvo22SsaNYfdPBldt6+dBcjH30nv

Malware Config

Extracted

Family

quasar

Version

1.4.1

Botnet

Office04

C2

94.228.166.40:4782

Mutex

172a89d7-b9b2-4d82-b5ed-6beb5326f544

Attributes
  • encryption_key

    7970C2029EDBB83E6BD65073BE18684AC9FF3F48

  • install_name

    KR6nDu9fLhop1bFe.exe

  • log_directory

    Logs

  • reconnect_delay

    3000

  • startup_key

    Defender.proces

  • subdirectory

    SubDir

Targets

    • Target

      164e19d48c8d3ed423d4d4c68dff47899f375b6ef4f2a27005562e16b3a8d33f.exe

    • Size

      3.1MB

    • MD5

      1b27e622f4edbbdd8fc93a0d1c129607

    • SHA1

      3e7b42dd10c01f632f158cc96701f6ba49ebec48

    • SHA256

      164e19d48c8d3ed423d4d4c68dff47899f375b6ef4f2a27005562e16b3a8d33f

    • SHA512

      bd6d609019f06649db920244a91ef5a2f105ea81055cdd53df72e737e1aae75b340060f45cb56383d201c154591a0a297fd69e1d09c5239b96ea5765a823ef5c

    • SSDEEP

      49152:kvHI22SsaNYfdPBldt698dBcjHn30LdBhJo2d/UTHHB72eh2NT:kvo22SsaNYfdPBldt6+dBcjH30nv

    • Quasar RAT

      Quasar is an open source Remote Access Tool.

    • Quasar payload

    • Executes dropped EXE

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Persistence

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Privilege Escalation

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Discovery

System Information Discovery

1
T1082

Query Registry

1
T1012

Tasks