General
-
Target
Loader.bat
-
Size
10.4MB
-
Sample
240627-c3lvwsyarg
-
MD5
4d8cc625098e8ffe5f8b5dbb3d45a3ee
-
SHA1
898d35c63b91f89d9ce399f17f400c979dd2b630
-
SHA256
3598244124cef26a1f17756cf140762178778257d0eed874873e7370c7f2524c
-
SHA512
0e408ec2698c5d6f05910fb5d61eacea5d88b24b7e0b4d150ac94e1b948fb2d0cd86bba92ba33d755e03ee85aaf072de7950a25cd9dc9b09bc6d168cd16d3c35
-
SSDEEP
49152:wVQDxc8uKGY1o5cnrdMEQ5A38d3tCYrTYWo9aftHuCimrCtSqE2Nb8qIM7+xORLS:Hy
Static task
static1
Malware Config
Extracted
quasar
-
reconnect_delay
3000
Extracted
quasar
1.4.1
Office04
history-foo.gl.at.ply.gg:42349
2beddbf7-c691-4058-94c7-f54389b4a581
-
encryption_key
CBFC5D217E55BEBDCD3A6EFA924299F76BC328D9
-
install_name
Client.exe
-
log_directory
Logs
-
reconnect_delay
3000
-
startup_key
Update
-
subdirectory
SubDir
Targets
-
-
Target
Loader.bat
-
Size
10.4MB
-
MD5
4d8cc625098e8ffe5f8b5dbb3d45a3ee
-
SHA1
898d35c63b91f89d9ce399f17f400c979dd2b630
-
SHA256
3598244124cef26a1f17756cf140762178778257d0eed874873e7370c7f2524c
-
SHA512
0e408ec2698c5d6f05910fb5d61eacea5d88b24b7e0b4d150ac94e1b948fb2d0cd86bba92ba33d755e03ee85aaf072de7950a25cd9dc9b09bc6d168cd16d3c35
-
SSDEEP
49152:wVQDxc8uKGY1o5cnrdMEQ5A38d3tCYrTYWo9aftHuCimrCtSqE2Nb8qIM7+xORLS:Hy
-
Quasar payload
-
Checks computer location settings
Looks up country code configured in the registry, likely geofence.
-
Executes dropped EXE
-
Loads dropped DLL
-