General

  • Target

    2024-06-24_c8015ef5fd4928a90e064f2ef5aebc97_icedid_poet-rat_quasar-rat_xrat

  • Size

    4.0MB

  • MD5

    c8015ef5fd4928a90e064f2ef5aebc97

  • SHA1

    e7258d245f886af77154fcb2838a1adadba34e94

  • SHA256

    97787cbf8314dfd67bbb56e12489e8900022b3c31565b275f479bcaa9b9e7557

  • SHA512

    9450336f760f3b1749f21203d992f3ef095164d3f1cf91ede05d157830a59e1a054b9c682fb5c6dee794604c944d34b7e03367bba03dbdcfbf51c1073d33010c

  • SSDEEP

    98304:Qh81Y4zw2GFvr22SsaNYfdPBldt6+dBcjHtKRJ6Bf:by2KM7jGIf

Score
10/10

Malware Config

Signatures

  • Detects Windows executables referencing non-Windows User-Agents 1 IoCs
  • Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers. 1 IoCs
  • Detects executables containing common artifacts observed in infostealers 1 IoCs
  • Quasar family
  • Quasar payload 1 IoCs
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • 2024-06-24_c8015ef5fd4928a90e064f2ef5aebc97_icedid_poet-rat_quasar-rat_xrat
    .exe windows:4 windows x86 arch:x86

    dbedb883647d887c5222e30abfa55f58


    Headers

    Imports

    Sections