General
-
Target
Client-built - Copie.exe
-
Size
3.1MB
-
Sample
240629-rtdkgszapb
-
MD5
c558a79e91fc7a650470b5013874ffa3
-
SHA1
c79d23530d3c3edecc9b84f100ac8000d83c5522
-
SHA256
38333105568fce734bdd879230abda47774869fa84ab37d956287d9ba197314c
-
SHA512
4c0c9137b780f77a2fe7b29bb90a389fc42077b03ea4dc4626cf728ac11050bb5f1043876d9011528ec323258168f89283b8d64af9ad6162af6577cff294e174
-
SSDEEP
98304:KvI22SsaNYfdPBldt6+dBcjHozRJ6/+W:8d7jeG+
Malware Config
Extracted
quasar
1.4.1
TESTIP
6.tcp.ngrok.io:19468
88de9d82-6909-427b-8a11-f28cf4280285
-
encryption_key
562515CBE0241F4FD48C91375ED3063F997D8AEE
-
install_name
Client.exe
-
log_directory
Logs
-
reconnect_delay
3000
-
startup_key
Quasar Client Startup
-
subdirectory
SubDir
Targets
-
-
Target
Client-built - Copie.exe
-
Size
3.1MB
-
MD5
c558a79e91fc7a650470b5013874ffa3
-
SHA1
c79d23530d3c3edecc9b84f100ac8000d83c5522
-
SHA256
38333105568fce734bdd879230abda47774869fa84ab37d956287d9ba197314c
-
SHA512
4c0c9137b780f77a2fe7b29bb90a389fc42077b03ea4dc4626cf728ac11050bb5f1043876d9011528ec323258168f89283b8d64af9ad6162af6577cff294e174
-
SSDEEP
98304:KvI22SsaNYfdPBldt6+dBcjHozRJ6/+W:8d7jeG+
-
Quasar payload
-
Legitimate hosting services abused for malware hosting/C2
-