General
-
Target
DriverInstall.exe
-
Size
3.1MB
-
MD5
2428d390c58c3ce2390bf4f6a00f27f2
-
SHA1
525322b7d43603e80d9d5c062baa9a1c4eb8c66f
-
SHA256
0b0f5f4a1afe5fc657325c8286e311c4b81a5ce7a516486b36ef7e5980dd120e
-
SHA512
d0a682e2b529e48b9f28fbef6d56c850c7a21ce03858755b28f4abe7ced2af6337f7b45e83f081faa37627f2e3d8a1dac46c3b75624478ed5f4ab33219e484b6
-
SSDEEP
49152:GvUt62XlaSFNWPjljiFa2RoUYIi3xh1v4LoGf7mTHHB72eh2NT:GvI62XlaSFNWPjljiFXRoUYIi3xK
Malware Config
Extracted
quasar
1.4.1
Office04
192.168.178.86:4782
bcb4ded3-f479-4472-930f-985b13a156fc
-
encryption_key
E65A63C5070648ABDC8CAD5F2CB118AA164CFD24
-
install_name
Client.exe
-
log_directory
Logs
-
reconnect_delay
3000
-
startup_key
Driver.exe
-
subdirectory
WOW646464
Signatures
-
Quasar family
-
Quasar payload 1 IoCs
Processes:
resource yara_rule sample family_quasar -
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource DriverInstall.exe
Files
-
DriverInstall.exe.exe windows:4 windows x86 arch:x86
f34d5f2d4577ed6d9ceec516c1f5a744
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
Imports
mscoree
_CorExeMain
Sections
.text Size: 3.1MB - Virtual size: 3.1MB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 3KB - Virtual size: 2KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ