General
-
Target
a451e748bc1e4c05bdaa722b35a5f6dd1a78765ac8967187a61b846f819c8bf6.exe
-
Size
3.1MB
-
Sample
240624-bpph7awelk
-
MD5
3a52e34c074990eee6ed67e3237c4c9c
-
SHA1
b7df84535c4d8002cdd7675866617cf9884455c6
-
SHA256
a451e748bc1e4c05bdaa722b35a5f6dd1a78765ac8967187a61b846f819c8bf6
-
SHA512
1553aa7e90b404f715c9b025937da6a4941fd287de9a69afe52e970731c48b3a6e62ae898a4e16164fa57e20183ff86999b37c7ff9c9f77fa0a85bce3916b19c
-
SSDEEP
49152:MvHI22SsaNYfdPBldt698dBcjHuZvgGoGnVvTHHB72eh2NT:Mvo22SsaNYfdPBldt6+dBcjHuZvF
Behavioral task
behavioral1
Sample
a451e748bc1e4c05bdaa722b35a5f6dd1a78765ac8967187a61b846f819c8bf6.exe
Resource
win7-20240611-en
Malware Config
Extracted
quasar
1.4.1
Office04
94.228.166.40:4782
172a89d7-b9b2-4d82-b5ed-6beb5326f544
-
encryption_key
7970C2029EDBB83E6BD65073BE18684AC9FF3F48
-
install_name
KR6nDu9fLhop1bFe.exe
-
log_directory
Logs
-
reconnect_delay
3000
-
startup_key
defender.proces
-
subdirectory
SubDir
Targets
-
-
Target
a451e748bc1e4c05bdaa722b35a5f6dd1a78765ac8967187a61b846f819c8bf6.exe
-
Size
3.1MB
-
MD5
3a52e34c074990eee6ed67e3237c4c9c
-
SHA1
b7df84535c4d8002cdd7675866617cf9884455c6
-
SHA256
a451e748bc1e4c05bdaa722b35a5f6dd1a78765ac8967187a61b846f819c8bf6
-
SHA512
1553aa7e90b404f715c9b025937da6a4941fd287de9a69afe52e970731c48b3a6e62ae898a4e16164fa57e20183ff86999b37c7ff9c9f77fa0a85bce3916b19c
-
SSDEEP
49152:MvHI22SsaNYfdPBldt698dBcjHuZvgGoGnVvTHHB72eh2NT:Mvo22SsaNYfdPBldt6+dBcjHuZvF
-
Quasar payload
-
Detects Windows executables referencing non-Windows User-Agents
-
Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers.
-
Detects executables containing common artifacts observed in infostealers
-
Executes dropped EXE
-