Analysis
-
max time kernel
1195s -
max time network
905s -
platform
windows7_x64 -
resource
win7-20240611-en -
resource tags
arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system -
submitted
29-06-2024 22:47
Behavioral task
behavioral1
Sample
sp00fer.exe
Resource
win7-20240611-en
General
-
Target
sp00fer.exe
-
Size
3.1MB
-
MD5
a121d9d691a400786000dee14a808ab1
-
SHA1
14ab065be3cfe0a7aa7808cb8891f7c75affc395
-
SHA256
7849231d077a00fd9129c2c6cecbb3287afc5656b8dfd263fdf57e2432d4f335
-
SHA512
e0a162b3d00ef69b96bd4a43f9a0c3297005e8a8db84233010d420bf87ff337ed4139b4cc27594fdd194416a03fe8a7be90b03a8f10e34b72f70d399d6917929
-
SSDEEP
49152:zvulL26AaNeWgPhlmVqvMQ7XSKLCO1JRLoGdFTHHB72eh2NT:zveL26AaNeWgPhlmVqkQ7XSKLCE
Malware Config
Extracted
quasar
1.4.1
Office04
pringelsy-51954.portmap.host:51954
6dc28d35-3024-44a7-a559-f9991015fa39
-
encryption_key
3107DF2D44BB6914C55BEA57D100135AB0F278DF
-
install_name
Client.exe
-
log_directory
Logs
-
reconnect_delay
799
-
startup_key
Quasar Client Startup
-
subdirectory
Common Files
Signatures
-
Quasar payload 62 IoCs
Processes:
resource yara_rule behavioral1/memory/2020-1-0x00000000000D0000-0x00000000003F4000-memory.dmp family_quasar C:\Program Files\Common Files\Client.exe family_quasar behavioral1/memory/2340-9-0x0000000000CC0000-0x0000000000FE4000-memory.dmp family_quasar behavioral1/memory/2656-23-0x0000000000050000-0x0000000000374000-memory.dmp family_quasar behavioral1/memory/2812-34-0x0000000000EA0000-0x00000000011C4000-memory.dmp family_quasar behavioral1/memory/2852-45-0x00000000013C0000-0x00000000016E4000-memory.dmp family_quasar behavioral1/memory/668-56-0x00000000003A0000-0x00000000006C4000-memory.dmp family_quasar behavioral1/memory/944-68-0x00000000008A0000-0x0000000000BC4000-memory.dmp family_quasar behavioral1/memory/2148-79-0x0000000000C30000-0x0000000000F54000-memory.dmp family_quasar behavioral1/memory/2084-90-0x0000000000200000-0x0000000000524000-memory.dmp family_quasar behavioral1/memory/2788-102-0x0000000000E50000-0x0000000001174000-memory.dmp family_quasar behavioral1/memory/1812-113-0x0000000000210000-0x0000000000534000-memory.dmp family_quasar behavioral1/memory/316-125-0x0000000000A70000-0x0000000000D94000-memory.dmp family_quasar behavioral1/memory/772-137-0x0000000001260000-0x0000000001584000-memory.dmp family_quasar behavioral1/memory/1816-149-0x0000000000010000-0x0000000000334000-memory.dmp family_quasar behavioral1/memory/2288-160-0x0000000000230000-0x0000000000554000-memory.dmp family_quasar behavioral1/memory/2420-172-0x00000000012F0000-0x0000000001614000-memory.dmp family_quasar behavioral1/memory/2868-214-0x0000000000280000-0x00000000005A4000-memory.dmp family_quasar behavioral1/memory/408-223-0x0000000000B10000-0x0000000000E34000-memory.dmp family_quasar behavioral1/memory/1964-232-0x0000000000130000-0x0000000000454000-memory.dmp family_quasar behavioral1/memory/3060-241-0x0000000001280000-0x00000000015A4000-memory.dmp family_quasar behavioral1/memory/1048-250-0x0000000000070000-0x0000000000394000-memory.dmp family_quasar behavioral1/memory/1576-259-0x0000000000C20000-0x0000000000F44000-memory.dmp family_quasar behavioral1/memory/2508-268-0x00000000013A0000-0x00000000016C4000-memory.dmp family_quasar behavioral1/memory/680-349-0x0000000000300000-0x0000000000624000-memory.dmp family_quasar behavioral1/memory/3056-358-0x0000000000D30000-0x0000000001054000-memory.dmp family_quasar behavioral1/memory/1308-383-0x0000000001080000-0x00000000013A4000-memory.dmp family_quasar behavioral1/memory/1696-400-0x0000000000260000-0x0000000000584000-memory.dmp family_quasar behavioral1/memory/2924-409-0x0000000001210000-0x0000000001534000-memory.dmp family_quasar behavioral1/memory/1332-442-0x0000000000090000-0x00000000003B4000-memory.dmp family_quasar behavioral1/memory/820-451-0x0000000000B80000-0x0000000000EA4000-memory.dmp family_quasar behavioral1/memory/2704-460-0x00000000010B0000-0x00000000013D4000-memory.dmp family_quasar behavioral1/memory/2776-469-0x00000000012E0000-0x0000000001604000-memory.dmp family_quasar behavioral1/memory/2480-486-0x0000000000D50000-0x0000000001074000-memory.dmp family_quasar behavioral1/memory/2700-495-0x0000000000030000-0x0000000000354000-memory.dmp family_quasar behavioral1/memory/560-504-0x0000000001140000-0x0000000001464000-memory.dmp family_quasar behavioral1/memory/1160-513-0x0000000001240000-0x0000000001564000-memory.dmp family_quasar behavioral1/memory/1548-530-0x00000000012B0000-0x00000000015D4000-memory.dmp family_quasar behavioral1/memory/2000-587-0x00000000002E0000-0x0000000000604000-memory.dmp family_quasar behavioral1/memory/1656-596-0x0000000000390000-0x00000000006B4000-memory.dmp family_quasar behavioral1/memory/1200-621-0x0000000001000000-0x0000000001324000-memory.dmp family_quasar behavioral1/memory/2028-638-0x0000000000850000-0x0000000000B74000-memory.dmp family_quasar behavioral1/memory/2628-671-0x0000000000DA0000-0x00000000010C4000-memory.dmp family_quasar behavioral1/memory/2972-680-0x0000000000E60000-0x0000000001184000-memory.dmp family_quasar behavioral1/memory/1608-697-0x0000000000360000-0x0000000000684000-memory.dmp family_quasar behavioral1/memory/2304-706-0x0000000000040000-0x0000000000364000-memory.dmp family_quasar behavioral1/memory/1476-715-0x0000000000E70000-0x0000000001194000-memory.dmp family_quasar behavioral1/memory/2988-724-0x0000000000170000-0x0000000000494000-memory.dmp family_quasar behavioral1/memory/960-773-0x0000000001370000-0x0000000001694000-memory.dmp family_quasar behavioral1/memory/2552-806-0x0000000000190000-0x00000000004B4000-memory.dmp family_quasar behavioral1/memory/1980-815-0x0000000000F20000-0x0000000001244000-memory.dmp family_quasar behavioral1/memory/448-824-0x0000000001090000-0x00000000013B4000-memory.dmp family_quasar behavioral1/memory/2680-833-0x00000000000E0000-0x0000000000404000-memory.dmp family_quasar behavioral1/memory/1704-842-0x0000000001390000-0x00000000016B4000-memory.dmp family_quasar behavioral1/memory/2448-939-0x00000000001C0000-0x00000000004E4000-memory.dmp family_quasar behavioral1/memory/2996-948-0x0000000000080000-0x00000000003A4000-memory.dmp family_quasar behavioral1/memory/2296-957-0x00000000009A0000-0x0000000000CC4000-memory.dmp family_quasar behavioral1/memory/1996-974-0x00000000013B0000-0x00000000016D4000-memory.dmp family_quasar behavioral1/memory/848-1007-0x00000000002B0000-0x00000000005D4000-memory.dmp family_quasar behavioral1/memory/3064-1016-0x0000000000EC0000-0x00000000011E4000-memory.dmp family_quasar behavioral1/memory/1972-1041-0x0000000000240000-0x0000000000564000-memory.dmp family_quasar behavioral1/memory/2676-1050-0x0000000000A90000-0x0000000000DB4000-memory.dmp family_quasar -
Executes dropped EXE 64 IoCs
Processes:
Client.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exepid process 2340 Client.exe 2656 Client.exe 2812 Client.exe 2852 Client.exe 668 Client.exe 944 Client.exe 2148 Client.exe 2084 Client.exe 2788 Client.exe 1812 Client.exe 316 Client.exe 772 Client.exe 1816 Client.exe 2288 Client.exe 2420 Client.exe 612 Client.exe 1652 Client.exe 1764 Client.exe 2868 Client.exe 408 Client.exe 1964 Client.exe 3060 Client.exe 1048 Client.exe 1576 Client.exe 2508 Client.exe 1864 Client.exe 1044 Client.exe 1880 Client.exe 2464 Client.exe 2128 Client.exe 2640 Client.exe 376 Client.exe 1284 Client.exe 2948 Client.exe 680 Client.exe 3056 Client.exe 2708 Client.exe 1596 Client.exe 1308 Client.exe 536 Client.exe 1696 Client.exe 2924 Client.exe 2644 Client.exe 2980 Client.exe 2336 Client.exe 1332 Client.exe 820 Client.exe 2704 Client.exe 2776 Client.exe 2388 Client.exe 2480 Client.exe 2700 Client.exe 560 Client.exe 1160 Client.exe 2660 Client.exe 1548 Client.exe 1820 Client.exe 1868 Client.exe 292 Client.exe 2244 Client.exe 2728 Client.exe 2208 Client.exe 2000 Client.exe 1656 Client.exe -
Drops file in Program Files directory 64 IoCs
Processes:
Client.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exedescription ioc process File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files\Client.exe Client.exe File opened for modification C:\Program Files\Common Files Client.exe File opened for modification C:\Program Files\Common Files Client.exe -
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Runs ping.exe 1 TTPs 64 IoCs
Processes:
PING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEpid process 1360 PING.EXE 2164 PING.EXE 1224 PING.EXE 1668 PING.EXE 2696 PING.EXE 1428 PING.EXE 2648 PING.EXE 844 PING.EXE 2968 PING.EXE 2200 PING.EXE 2664 PING.EXE 2936 PING.EXE 1712 PING.EXE 1316 PING.EXE 800 PING.EXE 2276 PING.EXE 2220 PING.EXE 2624 PING.EXE 1592 PING.EXE 2076 PING.EXE 2404 PING.EXE 2200 PING.EXE 1908 PING.EXE 1708 PING.EXE 2760 PING.EXE 1992 PING.EXE 880 PING.EXE 3024 PING.EXE 2844 PING.EXE 2608 PING.EXE 2488 PING.EXE 1884 PING.EXE 2492 PING.EXE 800 PING.EXE 2112 PING.EXE 2060 PING.EXE 1212 PING.EXE 1452 PING.EXE 2112 PING.EXE 1440 PING.EXE 1784 PING.EXE 2968 PING.EXE 1252 PING.EXE 2896 PING.EXE 324 PING.EXE 3064 PING.EXE 2008 PING.EXE 2068 PING.EXE 1704 PING.EXE 844 PING.EXE 2784 PING.EXE 408 PING.EXE 2736 PING.EXE 2240 PING.EXE 2436 PING.EXE 2588 PING.EXE 1928 PING.EXE 2488 PING.EXE 1084 PING.EXE 1088 PING.EXE 2008 PING.EXE 1360 PING.EXE 612 PING.EXE 2184 PING.EXE -
Scheduled Task/Job: Scheduled Task 1 TTPs 64 IoCs
Schtasks is often used by malware for persistence or to perform post-infection execution.
Processes:
schtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exepid process 1552 schtasks.exe 2564 schtasks.exe 2412 schtasks.exe 2696 schtasks.exe 2800 schtasks.exe 2888 schtasks.exe 1260 schtasks.exe 1040 schtasks.exe 2676 schtasks.exe 1972 schtasks.exe 1332 schtasks.exe 2432 schtasks.exe 2780 schtasks.exe 2020 schtasks.exe 1064 schtasks.exe 2432 schtasks.exe 2988 schtasks.exe 3000 schtasks.exe 988 schtasks.exe 2008 schtasks.exe 1376 schtasks.exe 1460 schtasks.exe 752 schtasks.exe 2320 schtasks.exe 1784 schtasks.exe 2408 schtasks.exe 1644 schtasks.exe 448 schtasks.exe 756 schtasks.exe 2996 schtasks.exe 1908 schtasks.exe 2648 schtasks.exe 2784 schtasks.exe 3052 schtasks.exe 1732 schtasks.exe 816 schtasks.exe 264 schtasks.exe 2360 schtasks.exe 2564 schtasks.exe 2660 schtasks.exe 2648 schtasks.exe 2896 schtasks.exe 2912 schtasks.exe 2200 schtasks.exe 2472 schtasks.exe 2108 schtasks.exe 2420 schtasks.exe 292 schtasks.exe 780 schtasks.exe 2780 schtasks.exe 268 schtasks.exe 1628 schtasks.exe 2808 schtasks.exe 1952 schtasks.exe 2296 schtasks.exe 2188 schtasks.exe 1364 schtasks.exe 3048 schtasks.exe 2368 schtasks.exe 1796 schtasks.exe 2488 schtasks.exe 2616 schtasks.exe 896 schtasks.exe 2484 schtasks.exe -
Suspicious use of AdjustPrivilegeToken 64 IoCs
Processes:
sp00fer.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exedescription pid process Token: SeDebugPrivilege 2020 sp00fer.exe Token: SeDebugPrivilege 2340 Client.exe Token: SeDebugPrivilege 2656 Client.exe Token: SeDebugPrivilege 2812 Client.exe Token: SeDebugPrivilege 2852 Client.exe Token: SeDebugPrivilege 668 Client.exe Token: SeDebugPrivilege 944 Client.exe Token: SeDebugPrivilege 2148 Client.exe Token: SeDebugPrivilege 2084 Client.exe Token: SeDebugPrivilege 2788 Client.exe Token: SeDebugPrivilege 1812 Client.exe Token: SeDebugPrivilege 316 Client.exe Token: SeDebugPrivilege 772 Client.exe Token: SeDebugPrivilege 1816 Client.exe Token: SeDebugPrivilege 2288 Client.exe Token: SeDebugPrivilege 2420 Client.exe Token: SeDebugPrivilege 612 Client.exe Token: SeDebugPrivilege 1652 Client.exe Token: SeDebugPrivilege 1764 Client.exe Token: SeDebugPrivilege 2868 Client.exe Token: SeDebugPrivilege 408 Client.exe Token: SeDebugPrivilege 1964 Client.exe Token: SeDebugPrivilege 3060 Client.exe Token: SeDebugPrivilege 1048 Client.exe Token: SeDebugPrivilege 1576 Client.exe Token: SeDebugPrivilege 2508 Client.exe Token: SeDebugPrivilege 1864 Client.exe Token: SeDebugPrivilege 1044 Client.exe Token: SeDebugPrivilege 1880 Client.exe Token: SeDebugPrivilege 2464 Client.exe Token: SeDebugPrivilege 2128 Client.exe Token: SeDebugPrivilege 2640 Client.exe Token: SeDebugPrivilege 376 Client.exe Token: SeDebugPrivilege 1284 Client.exe Token: SeDebugPrivilege 2948 Client.exe Token: SeDebugPrivilege 680 Client.exe Token: SeDebugPrivilege 3056 Client.exe Token: SeDebugPrivilege 2708 Client.exe Token: SeDebugPrivilege 1596 Client.exe Token: SeDebugPrivilege 1308 Client.exe Token: SeDebugPrivilege 536 Client.exe Token: SeDebugPrivilege 1696 Client.exe Token: SeDebugPrivilege 2924 Client.exe Token: SeDebugPrivilege 2644 Client.exe Token: SeDebugPrivilege 2980 Client.exe Token: SeDebugPrivilege 2336 Client.exe Token: SeDebugPrivilege 1332 Client.exe Token: SeDebugPrivilege 820 Client.exe Token: SeDebugPrivilege 2704 Client.exe Token: SeDebugPrivilege 2776 Client.exe Token: SeDebugPrivilege 2388 Client.exe Token: SeDebugPrivilege 2480 Client.exe Token: SeDebugPrivilege 2700 Client.exe Token: SeDebugPrivilege 560 Client.exe Token: SeDebugPrivilege 1160 Client.exe Token: SeDebugPrivilege 2660 Client.exe Token: SeDebugPrivilege 1548 Client.exe Token: SeDebugPrivilege 1820 Client.exe Token: SeDebugPrivilege 1868 Client.exe Token: SeDebugPrivilege 292 Client.exe Token: SeDebugPrivilege 2244 Client.exe Token: SeDebugPrivilege 2728 Client.exe Token: SeDebugPrivilege 2208 Client.exe Token: SeDebugPrivilege 2000 Client.exe -
Suspicious use of FindShellTrayWindow 64 IoCs
Processes:
Client.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exepid process 2340 Client.exe 2656 Client.exe 2812 Client.exe 2852 Client.exe 668 Client.exe 944 Client.exe 2148 Client.exe 2084 Client.exe 2788 Client.exe 1812 Client.exe 316 Client.exe 772 Client.exe 1816 Client.exe 2288 Client.exe 2420 Client.exe 612 Client.exe 1652 Client.exe 1764 Client.exe 2868 Client.exe 408 Client.exe 1964 Client.exe 3060 Client.exe 1048 Client.exe 1576 Client.exe 2508 Client.exe 1864 Client.exe 1044 Client.exe 1880 Client.exe 2464 Client.exe 2128 Client.exe 2640 Client.exe 376 Client.exe 1284 Client.exe 2948 Client.exe 680 Client.exe 3056 Client.exe 2708 Client.exe 1596 Client.exe 1308 Client.exe 536 Client.exe 1696 Client.exe 2924 Client.exe 2644 Client.exe 2980 Client.exe 2336 Client.exe 1332 Client.exe 820 Client.exe 2704 Client.exe 2776 Client.exe 2388 Client.exe 2480 Client.exe 2700 Client.exe 560 Client.exe 1160 Client.exe 2660 Client.exe 1548 Client.exe 1820 Client.exe 1868 Client.exe 292 Client.exe 2244 Client.exe 2728 Client.exe 2208 Client.exe 2000 Client.exe 1656 Client.exe -
Suspicious use of SendNotifyMessage 64 IoCs
Processes:
Client.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exeClient.exepid process 2340 Client.exe 2656 Client.exe 2812 Client.exe 2852 Client.exe 668 Client.exe 944 Client.exe 2148 Client.exe 2084 Client.exe 2788 Client.exe 1812 Client.exe 316 Client.exe 772 Client.exe 1816 Client.exe 2288 Client.exe 2420 Client.exe 612 Client.exe 1652 Client.exe 1764 Client.exe 2868 Client.exe 408 Client.exe 1964 Client.exe 3060 Client.exe 1048 Client.exe 1576 Client.exe 2508 Client.exe 1864 Client.exe 1044 Client.exe 1880 Client.exe 2464 Client.exe 2128 Client.exe 2640 Client.exe 376 Client.exe 1284 Client.exe 2948 Client.exe 680 Client.exe 3056 Client.exe 2708 Client.exe 1596 Client.exe 1308 Client.exe 536 Client.exe 1696 Client.exe 2924 Client.exe 2644 Client.exe 2980 Client.exe 2336 Client.exe 1332 Client.exe 820 Client.exe 2704 Client.exe 2776 Client.exe 2388 Client.exe 2480 Client.exe 2700 Client.exe 560 Client.exe 1160 Client.exe 2660 Client.exe 1548 Client.exe 1820 Client.exe 1868 Client.exe 292 Client.exe 2244 Client.exe 2728 Client.exe 2208 Client.exe 2000 Client.exe 1656 Client.exe -
Suspicious use of WriteProcessMemory 64 IoCs
Processes:
sp00fer.exeClient.execmd.exeClient.execmd.exeClient.execmd.exeClient.execmd.exedescription pid process target process PID 2020 wrote to memory of 2420 2020 sp00fer.exe schtasks.exe PID 2020 wrote to memory of 2420 2020 sp00fer.exe schtasks.exe PID 2020 wrote to memory of 2420 2020 sp00fer.exe schtasks.exe PID 2020 wrote to memory of 2340 2020 sp00fer.exe Client.exe PID 2020 wrote to memory of 2340 2020 sp00fer.exe Client.exe PID 2020 wrote to memory of 2340 2020 sp00fer.exe Client.exe PID 2340 wrote to memory of 2648 2340 Client.exe schtasks.exe PID 2340 wrote to memory of 2648 2340 Client.exe schtasks.exe PID 2340 wrote to memory of 2648 2340 Client.exe schtasks.exe PID 2340 wrote to memory of 2792 2340 Client.exe cmd.exe PID 2340 wrote to memory of 2792 2340 Client.exe cmd.exe PID 2340 wrote to memory of 2792 2340 Client.exe cmd.exe PID 2792 wrote to memory of 2088 2792 cmd.exe chcp.com PID 2792 wrote to memory of 2088 2792 cmd.exe chcp.com PID 2792 wrote to memory of 2088 2792 cmd.exe chcp.com PID 2792 wrote to memory of 2636 2792 cmd.exe PING.EXE PID 2792 wrote to memory of 2636 2792 cmd.exe PING.EXE PID 2792 wrote to memory of 2636 2792 cmd.exe PING.EXE PID 2792 wrote to memory of 2656 2792 cmd.exe Client.exe PID 2792 wrote to memory of 2656 2792 cmd.exe Client.exe PID 2792 wrote to memory of 2656 2792 cmd.exe Client.exe PID 2656 wrote to memory of 1972 2656 Client.exe schtasks.exe PID 2656 wrote to memory of 1972 2656 Client.exe schtasks.exe PID 2656 wrote to memory of 1972 2656 Client.exe schtasks.exe PID 2656 wrote to memory of 3016 2656 Client.exe cmd.exe PID 2656 wrote to memory of 3016 2656 Client.exe cmd.exe PID 2656 wrote to memory of 3016 2656 Client.exe cmd.exe PID 3016 wrote to memory of 1200 3016 cmd.exe chcp.com PID 3016 wrote to memory of 1200 3016 cmd.exe chcp.com PID 3016 wrote to memory of 1200 3016 cmd.exe chcp.com PID 3016 wrote to memory of 1812 3016 cmd.exe PING.EXE PID 3016 wrote to memory of 1812 3016 cmd.exe PING.EXE PID 3016 wrote to memory of 1812 3016 cmd.exe PING.EXE PID 3016 wrote to memory of 2812 3016 cmd.exe Client.exe PID 3016 wrote to memory of 2812 3016 cmd.exe Client.exe PID 3016 wrote to memory of 2812 3016 cmd.exe Client.exe PID 2812 wrote to memory of 1596 2812 Client.exe schtasks.exe PID 2812 wrote to memory of 1596 2812 Client.exe schtasks.exe PID 2812 wrote to memory of 1596 2812 Client.exe schtasks.exe PID 2812 wrote to memory of 2028 2812 Client.exe cmd.exe PID 2812 wrote to memory of 2028 2812 Client.exe cmd.exe PID 2812 wrote to memory of 2028 2812 Client.exe cmd.exe PID 2028 wrote to memory of 1476 2028 cmd.exe chcp.com PID 2028 wrote to memory of 1476 2028 cmd.exe chcp.com PID 2028 wrote to memory of 1476 2028 cmd.exe chcp.com PID 2028 wrote to memory of 1360 2028 cmd.exe PING.EXE PID 2028 wrote to memory of 1360 2028 cmd.exe PING.EXE PID 2028 wrote to memory of 1360 2028 cmd.exe PING.EXE PID 2028 wrote to memory of 2852 2028 cmd.exe Client.exe PID 2028 wrote to memory of 2852 2028 cmd.exe Client.exe PID 2028 wrote to memory of 2852 2028 cmd.exe Client.exe PID 2852 wrote to memory of 816 2852 Client.exe schtasks.exe PID 2852 wrote to memory of 816 2852 Client.exe schtasks.exe PID 2852 wrote to memory of 816 2852 Client.exe schtasks.exe PID 2852 wrote to memory of 2096 2852 Client.exe cmd.exe PID 2852 wrote to memory of 2096 2852 Client.exe cmd.exe PID 2852 wrote to memory of 2096 2852 Client.exe cmd.exe PID 2096 wrote to memory of 1988 2096 cmd.exe chcp.com PID 2096 wrote to memory of 1988 2096 cmd.exe chcp.com PID 2096 wrote to memory of 1988 2096 cmd.exe chcp.com PID 2096 wrote to memory of 1864 2096 cmd.exe PING.EXE PID 2096 wrote to memory of 1864 2096 cmd.exe PING.EXE PID 2096 wrote to memory of 1864 2096 cmd.exe PING.EXE PID 2096 wrote to memory of 668 2096 cmd.exe Client.exe -
Uses Task Scheduler COM API 1 TTPs
The Task Scheduler COM API can be used to schedule applications to run on boot or at set times.
Processes
-
C:\Users\Admin\AppData\Local\Temp\sp00fer.exe"C:\Users\Admin\AppData\Local\Temp\sp00fer.exe"1⤵
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f2⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"2⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
- Suspicious use of WriteProcessMemory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f3⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\QgRYu8XkixsI.bat" "3⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\system32\chcp.comchcp 650014⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost4⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"4⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
- Suspicious use of WriteProcessMemory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f5⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\DCdLUOfPtAWT.bat" "5⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\system32\chcp.comchcp 650016⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost6⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"6⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
- Suspicious use of WriteProcessMemory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f7⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\JES2OJ5AlNvR.bat" "7⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\system32\chcp.comchcp 650018⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost8⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"8⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
- Suspicious use of WriteProcessMemory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f9⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\NrgzEmf3vT8D.bat" "9⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\system32\chcp.comchcp 6500110⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost10⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"10⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f11⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\NPNcEMLGIDOV.bat" "11⤵
-
C:\Windows\system32\chcp.comchcp 6500112⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost12⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"12⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f13⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\VSaK6BsdO5HS.bat" "13⤵
-
C:\Windows\system32\chcp.comchcp 6500114⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost14⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"14⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f15⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\q3ssle8pWLKP.bat" "15⤵
-
C:\Windows\system32\chcp.comchcp 6500116⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost16⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"16⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f17⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\BxF8TPj72Bvj.bat" "17⤵
-
C:\Windows\system32\chcp.comchcp 6500118⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost18⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"18⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f19⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\Im4pvohi1Crg.bat" "19⤵
-
C:\Windows\system32\chcp.comchcp 6500120⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost20⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"20⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f21⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\1tjLsHvlbGBD.bat" "21⤵
-
C:\Windows\system32\chcp.comchcp 6500122⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost22⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"22⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f23⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\TmOTIb3kldzL.bat" "23⤵
-
C:\Windows\system32\chcp.comchcp 6500124⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost24⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"24⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f25⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\QIjYzwQ42Z9F.bat" "25⤵
-
C:\Windows\system32\chcp.comchcp 6500126⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost26⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"26⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f27⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\FJWWaKGavioN.bat" "27⤵
-
C:\Windows\system32\chcp.comchcp 6500128⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost28⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"28⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f29⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\wd4FUKrPJxew.bat" "29⤵
-
C:\Windows\system32\chcp.comchcp 6500130⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost30⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"30⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f31⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\x6g5YWHPYIIi.bat" "31⤵
-
C:\Windows\system32\chcp.comchcp 6500132⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost32⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"32⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f33⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\fjqFj0HmoEim.bat" "33⤵
-
C:\Windows\system32\chcp.comchcp 6500134⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost34⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"34⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f35⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\cfNa7oQkuiZg.bat" "35⤵
-
C:\Windows\system32\chcp.comchcp 6500136⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost36⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"36⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f37⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\PEYdhoaeOXf8.bat" "37⤵
-
C:\Windows\system32\chcp.comchcp 6500138⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost38⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"38⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f39⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\6ioLPO1Zr2Kq.bat" "39⤵
-
C:\Windows\system32\chcp.comchcp 6500140⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost40⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"40⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f41⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\nF7cMDcwOZnu.bat" "41⤵
-
C:\Windows\system32\chcp.comchcp 6500142⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost42⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"42⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f43⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\1QeM9VAuG6w4.bat" "43⤵
-
C:\Windows\system32\chcp.comchcp 6500144⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost44⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"44⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f45⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\O0nHL2rN8lsh.bat" "45⤵
-
C:\Windows\system32\chcp.comchcp 6500146⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost46⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"46⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f47⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\WmsjofwZJhFH.bat" "47⤵
-
C:\Windows\system32\chcp.comchcp 6500148⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost48⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"48⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f49⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\GYytgcbQkxep.bat" "49⤵
-
C:\Windows\system32\chcp.comchcp 6500150⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost50⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"50⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f51⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\9sBlTwlaEOsz.bat" "51⤵
-
C:\Windows\system32\chcp.comchcp 6500152⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost52⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"52⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f53⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\zdLnro68UX0f.bat" "53⤵
-
C:\Windows\system32\chcp.comchcp 6500154⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost54⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"54⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f55⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\RpkR7A2ov1Kw.bat" "55⤵
-
C:\Windows\system32\chcp.comchcp 6500156⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost56⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"56⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f57⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\feGSUUNpl4vL.bat" "57⤵
-
C:\Windows\system32\chcp.comchcp 6500158⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost58⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"58⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f59⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\ug1nigOUrpRu.bat" "59⤵
-
C:\Windows\system32\chcp.comchcp 6500160⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost60⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"60⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f61⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\GLq3QkdvJzuh.bat" "61⤵
-
C:\Windows\system32\chcp.comchcp 6500162⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost62⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"62⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f63⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\gj09BPDQZsEB.bat" "63⤵
-
C:\Windows\system32\chcp.comchcp 6500164⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost64⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"64⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f65⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\56XK20SDirD8.bat" "65⤵
-
C:\Windows\system32\chcp.comchcp 6500166⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost66⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"66⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f67⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\CBNebGtFyYjR.bat" "67⤵
-
C:\Windows\system32\chcp.comchcp 6500168⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost68⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"68⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f69⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\exCh1nbx8cU5.bat" "69⤵
-
C:\Windows\system32\chcp.comchcp 6500170⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost70⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"70⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f71⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\JgkUUkacFyOD.bat" "71⤵
-
C:\Windows\system32\chcp.comchcp 6500172⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost72⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"72⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f73⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\mk7S78LKNuuc.bat" "73⤵
-
C:\Windows\system32\chcp.comchcp 6500174⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost74⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"74⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f75⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\x6N6sGf86s9W.bat" "75⤵
-
C:\Windows\system32\chcp.comchcp 6500176⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost76⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"76⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f77⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\uWnXaMnQRdkW.bat" "77⤵
-
C:\Windows\system32\chcp.comchcp 6500178⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost78⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"78⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f79⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\8u5vKSAzCgif.bat" "79⤵
-
C:\Windows\system32\chcp.comchcp 6500180⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost80⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"80⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f81⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\KWZdMpV7hP4z.bat" "81⤵
-
C:\Windows\system32\chcp.comchcp 6500182⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost82⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"82⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f83⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\06gbc4VOjpZj.bat" "83⤵
-
C:\Windows\system32\chcp.comchcp 6500184⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost84⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"84⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f85⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\Kl4Ca7bgrea4.bat" "85⤵
-
C:\Windows\system32\chcp.comchcp 6500186⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost86⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"86⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f87⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\1WrdTlk4MdFr.bat" "87⤵
-
C:\Windows\system32\chcp.comchcp 6500188⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost88⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"88⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f89⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\QHvOYB3hvqDa.bat" "89⤵
-
C:\Windows\system32\chcp.comchcp 6500190⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost90⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"90⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f91⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\FY04I38RorxR.bat" "91⤵
-
C:\Windows\system32\chcp.comchcp 6500192⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost92⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"92⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f93⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\SYWsIhTBCDh7.bat" "93⤵
-
C:\Windows\system32\chcp.comchcp 6500194⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost94⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"94⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f95⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\hv58tvBzLycd.bat" "95⤵
-
C:\Windows\system32\chcp.comchcp 6500196⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost96⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"96⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f97⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\BjlBbRNqoOoe.bat" "97⤵
-
C:\Windows\system32\chcp.comchcp 6500198⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost98⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"98⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f99⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\ZPFz8AM6rFkd.bat" "99⤵
-
C:\Windows\system32\chcp.comchcp 65001100⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost100⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"100⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f101⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\xhI9dpLDNewe.bat" "101⤵
-
C:\Windows\system32\chcp.comchcp 65001102⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost102⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"102⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f103⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\vSKzuMNtlea0.bat" "103⤵
-
C:\Windows\system32\chcp.comchcp 65001104⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost104⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"104⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f105⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\FeG760l7rphU.bat" "105⤵
-
C:\Windows\system32\chcp.comchcp 65001106⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost106⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"106⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f107⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\VLN1xVbDBPDG.bat" "107⤵
-
C:\Windows\system32\chcp.comchcp 65001108⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost108⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"108⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f109⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\4e1CeYBhUV4G.bat" "109⤵
-
C:\Windows\system32\chcp.comchcp 65001110⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost110⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"110⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f111⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\899o92IVorj7.bat" "111⤵
-
C:\Windows\system32\chcp.comchcp 65001112⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost112⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"112⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f113⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\k2uDCZevVKC5.bat" "113⤵
-
C:\Windows\system32\chcp.comchcp 65001114⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost114⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"114⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f115⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\LKWRiNCQAq4Y.bat" "115⤵
-
C:\Windows\system32\chcp.comchcp 65001116⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost116⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"116⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f117⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\6QaiGLBCuMtZ.bat" "117⤵
-
C:\Windows\system32\chcp.comchcp 65001118⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost118⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"118⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f119⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\1VsU7nt9sqf4.bat" "119⤵
-
C:\Windows\system32\chcp.comchcp 65001120⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost120⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"120⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f121⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\gmJtRpRcb1jb.bat" "121⤵
-
C:\Windows\system32\chcp.comchcp 65001122⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost122⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"122⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f123⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\72a4u6s0c4jp.bat" "123⤵
-
C:\Windows\system32\chcp.comchcp 65001124⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost124⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"124⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f125⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\qz7PLUacFAdO.bat" "125⤵
-
C:\Windows\system32\chcp.comchcp 65001126⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost126⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"126⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f127⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\JZa78WXT7M7P.bat" "127⤵
-
C:\Windows\system32\chcp.comchcp 65001128⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost128⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"128⤵
- Executes dropped EXE
- Drops file in Program Files directory
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f129⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\sgIP8R08p00A.bat" "129⤵
-
C:\Windows\system32\chcp.comchcp 65001130⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost130⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"130⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f131⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\J20mkx27t1ry.bat" "131⤵
-
C:\Windows\system32\chcp.comchcp 65001132⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost132⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"132⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f133⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\Pa3cGyHHqPcc.bat" "133⤵
-
C:\Windows\system32\chcp.comchcp 65001134⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost134⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"134⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f135⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\suTh7XtuAnvk.bat" "135⤵
-
C:\Windows\system32\chcp.comchcp 65001136⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost136⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"136⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f137⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\r8CsJGu6RYjU.bat" "137⤵
-
C:\Windows\system32\chcp.comchcp 65001138⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost138⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"138⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f139⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\I2KlgRtip72Z.bat" "139⤵
-
C:\Windows\system32\chcp.comchcp 65001140⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost140⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"140⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f141⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\HuNcMOj5KXtQ.bat" "141⤵
-
C:\Windows\system32\chcp.comchcp 65001142⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost142⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"142⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f143⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\FNyTOF0EjvpI.bat" "143⤵
-
C:\Windows\system32\chcp.comchcp 65001144⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost144⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"144⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f145⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\QxiX5IS7ntvV.bat" "145⤵
-
C:\Windows\system32\chcp.comchcp 65001146⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost146⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"146⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f147⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\MHz6Xuy6l7Pn.bat" "147⤵
-
C:\Windows\system32\chcp.comchcp 65001148⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost148⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"148⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f149⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\d8EoKm9bj911.bat" "149⤵
-
C:\Windows\system32\chcp.comchcp 65001150⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost150⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"150⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f151⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\4Nk9OxTAQvAf.bat" "151⤵
-
C:\Windows\system32\chcp.comchcp 65001152⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost152⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"152⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f153⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\PR8SFirmmaqg.bat" "153⤵
-
C:\Windows\system32\chcp.comchcp 65001154⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost154⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"154⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f155⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\yvwYHpHnJAmM.bat" "155⤵
-
C:\Windows\system32\chcp.comchcp 65001156⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost156⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"156⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f157⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\z3VODNkDwK3T.bat" "157⤵
-
C:\Windows\system32\chcp.comchcp 65001158⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost158⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"158⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f159⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\3KBJ46ilhneH.bat" "159⤵
-
C:\Windows\system32\chcp.comchcp 65001160⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost160⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"160⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f161⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\4ELZfM44Pkrg.bat" "161⤵
-
C:\Windows\system32\chcp.comchcp 65001162⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost162⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"162⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f163⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\98l3zKYIT7Ce.bat" "163⤵
-
C:\Windows\system32\chcp.comchcp 65001164⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost164⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"164⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f165⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\Q1dNfiNfddH1.bat" "165⤵
-
C:\Windows\system32\chcp.comchcp 65001166⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost166⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"166⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f167⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\CxeR9AWNtxJR.bat" "167⤵
-
C:\Windows\system32\chcp.comchcp 65001168⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost168⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"168⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f169⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\YZh9nAN7xbYE.bat" "169⤵
-
C:\Windows\system32\chcp.comchcp 65001170⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost170⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"170⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f171⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\KyvQ4OX44182.bat" "171⤵
-
C:\Windows\system32\chcp.comchcp 65001172⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost172⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"172⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f173⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\9jp43bBjsDWM.bat" "173⤵
-
C:\Windows\system32\chcp.comchcp 65001174⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost174⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"174⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f175⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\LAyxA36bF60A.bat" "175⤵
-
C:\Windows\system32\chcp.comchcp 65001176⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost176⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"176⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f177⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\mFqg6DYNq88m.bat" "177⤵
-
C:\Windows\system32\chcp.comchcp 65001178⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost178⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"178⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f179⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\dwgUi0AChpoq.bat" "179⤵
-
C:\Windows\system32\chcp.comchcp 65001180⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost180⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"180⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f181⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\GOl6cyhctgJU.bat" "181⤵
-
C:\Windows\system32\chcp.comchcp 65001182⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost182⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"182⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f183⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\jg83utsisLlW.bat" "183⤵
-
C:\Windows\system32\chcp.comchcp 65001184⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost184⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"184⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f185⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\PI9wIfsMuIfN.bat" "185⤵
-
C:\Windows\system32\chcp.comchcp 65001186⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost186⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"186⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f187⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\WXfWyKpNUqdp.bat" "187⤵
-
C:\Windows\system32\chcp.comchcp 65001188⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost188⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"188⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f189⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\TmteVaG1FIRz.bat" "189⤵
-
C:\Windows\system32\chcp.comchcp 65001190⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost190⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"190⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f191⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\dnKMEh4SZn4u.bat" "191⤵
-
C:\Windows\system32\chcp.comchcp 65001192⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost192⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"192⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f193⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\qe3P26sZImqU.bat" "193⤵
-
C:\Windows\system32\chcp.comchcp 65001194⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost194⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"194⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f195⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\52nadDRuniio.bat" "195⤵
-
C:\Windows\system32\chcp.comchcp 65001196⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost196⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"196⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f197⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\gvBEAuREwxmS.bat" "197⤵
-
C:\Windows\system32\chcp.comchcp 65001198⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost198⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"198⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f199⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\NcPz9GhwmM4t.bat" "199⤵
-
C:\Windows\system32\chcp.comchcp 65001200⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost200⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"200⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f201⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\rDCUao8J4Nhw.bat" "201⤵
-
C:\Windows\system32\chcp.comchcp 65001202⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost202⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"202⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f203⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\IQDa5zikl9Fu.bat" "203⤵
-
C:\Windows\system32\chcp.comchcp 65001204⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost204⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"204⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f205⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\8nfvfm4FYZ1X.bat" "205⤵
-
C:\Windows\system32\chcp.comchcp 65001206⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost206⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"206⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f207⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\McITpRt0OaOq.bat" "207⤵
-
C:\Windows\system32\chcp.comchcp 65001208⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost208⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"208⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f209⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\kYuk9GU2cxCZ.bat" "209⤵
-
C:\Windows\system32\chcp.comchcp 65001210⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost210⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"210⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f211⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\uDbmeyngwxLU.bat" "211⤵
-
C:\Windows\system32\chcp.comchcp 65001212⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost212⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"212⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f213⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\8oVvV0luTdff.bat" "213⤵
-
C:\Windows\system32\chcp.comchcp 65001214⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost214⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"214⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f215⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\YGdpnK5FHtKI.bat" "215⤵
-
C:\Windows\system32\chcp.comchcp 65001216⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost216⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"216⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f217⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\Q4zocqnFLh9a.bat" "217⤵
-
C:\Windows\system32\chcp.comchcp 65001218⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost218⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"218⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f219⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\Wr7mpSMFkuFa.bat" "219⤵
-
C:\Windows\system32\chcp.comchcp 65001220⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost220⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"220⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f221⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\czPRdpVmyLK8.bat" "221⤵
-
C:\Windows\system32\chcp.comchcp 65001222⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost222⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"222⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f223⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\f4kubUmMgLs0.bat" "223⤵
-
C:\Windows\system32\chcp.comchcp 65001224⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost224⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"224⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f225⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\nQEmsIWfenom.bat" "225⤵
-
C:\Windows\system32\chcp.comchcp 65001226⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost226⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"226⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f227⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\eg6Wl1mdBvvu.bat" "227⤵
-
C:\Windows\system32\chcp.comchcp 65001228⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost228⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"228⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f229⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\DbCkH5Jbpwhh.bat" "229⤵
-
C:\Windows\system32\chcp.comchcp 65001230⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost230⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"230⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f231⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\eXmnDnhkHld7.bat" "231⤵
-
C:\Windows\system32\chcp.comchcp 65001232⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost232⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"232⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f233⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\HWZg5RyGX5O7.bat" "233⤵
-
C:\Windows\system32\chcp.comchcp 65001234⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost234⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"234⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f235⤵
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\Wi0LX0lYvr1G.bat" "235⤵
-
C:\Windows\system32\chcp.comchcp 65001236⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost236⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"236⤵
- Drops file in Program Files directory
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f237⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\8pfO59ue7cyY.bat" "237⤵
-
C:\Windows\system32\chcp.comchcp 65001238⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost238⤵
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"238⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f239⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\cmd.execmd /c ""C:\Users\Admin\AppData\Local\Temp\qLIuMqAfmeDC.bat" "239⤵
-
C:\Windows\system32\chcp.comchcp 65001240⤵
-
C:\Windows\system32\PING.EXEping -n 10 localhost240⤵
- Runs ping.exe
-
C:\Program Files\Common Files\Client.exe"C:\Program Files\Common Files\Client.exe"240⤵
-
C:\Windows\system32\schtasks.exe"schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Program Files\Common Files\Client.exe" /rl HIGHEST /f241⤵
- Scheduled Task/Job: Scheduled Task