General

  • Target

    1b27e622f4edbbdd8fc93a0d1c129607.bin

  • Size

    1.2MB

  • MD5

    d2535e9cb08f9ca169bdec719f66b917

  • SHA1

    931f64a688d24560b6597e3037bcd3a1b1294810

  • SHA256

    0dfb26997cbb3504d382426b12fdf19b0a933520cb3a46035924381b298968fd

  • SHA512

    3173bb62691521ae59d65d5f729013e7f135e6b10e2c1ee534d9f3f619fe5220f4635b185c7d202612d005d18857c8025a255ee91f84a45ec3276add4224d10b

  • SSDEEP

    24576:sAGSmvJ7JxMiEOeDF1wMkjTdSAWvWvyZWoerW84vzzHJgj:s57JxJKrwMaTdSAUIoeVgzHJK

Score
10/10

Malware Config

Extracted

Family

quasar

Version

1.4.1

Botnet

Office04

C2

94.228.166.40:4782

Mutex

172a89d7-b9b2-4d82-b5ed-6beb5326f544

Attributes
  • encryption_key

    7970C2029EDBB83E6BD65073BE18684AC9FF3F48

  • install_name

    KR6nDu9fLhop1bFe.exe

  • log_directory

    Logs

  • reconnect_delay

    3000

  • startup_key

    Defender.proces

  • subdirectory

    SubDir

Signatures

  • Quasar family
  • Quasar payload 1 IoCs
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • 1b27e622f4edbbdd8fc93a0d1c129607.bin
    .zip

    Password: infected

  • 164e19d48c8d3ed423d4d4c68dff47899f375b6ef4f2a27005562e16b3a8d33f.exe
    .exe windows:4 windows x86 arch:x86

    Password: infected

    f34d5f2d4577ed6d9ceec516c1f5a744


    Headers

    Imports

    Sections