General
-
Target
wave generator (Private Build).zip
-
Size
1.2MB
-
Sample
240630-sxcb9szejc
-
MD5
11ccf636f2b9394a7b730ee21191ed0f
-
SHA1
8cf3aacf151a82a0b9e8d056024669b8ddf78f4d
-
SHA256
b1c44de49c36d63e36b97e92454b023ca5bd940c373459cd545803eaf331f900
-
SHA512
575a8258cd93bfacc37a28464d115ac5746f0515097fc8742bf0064399d93b52587160977af518298f2a9a4a10543f462917bfe29399e032f775961698072be8
-
SSDEEP
24576:1bKdVyx5LayYY3jEJCnRVVC5HLdeyaUE982LtJTAWyIywFvC98Zx:1bAIx5jJj/RVVC5HLYE2097wpCWZx
Behavioral task
behavioral1
Sample
wave generator (Private Build).zip
Resource
win7-20231129-en
Behavioral task
behavioral2
Sample
wave generator (Private Build).zip
Resource
win10v2004-20240508-en
Behavioral task
behavioral3
Sample
Client-built.exe
Resource
win7-20240611-en
Malware Config
Extracted
quasar
1.4.1
Office04
192.168.1.150:4782
4fa54cdc-4bee-4759-b0fd-21bb6d6f9eed
-
encryption_key
99A3D9CE1DE6501187FC4C0E50EBB3FE8AD7B9A8
-
install_name
Client.exe
-
log_directory
Logs
-
reconnect_delay
3000
-
startup_key
Microsoft Task Manager Worker Service
-
subdirectory
SubDir
Targets
-
-
Target
wave generator (Private Build).zip
-
Size
1.2MB
-
MD5
11ccf636f2b9394a7b730ee21191ed0f
-
SHA1
8cf3aacf151a82a0b9e8d056024669b8ddf78f4d
-
SHA256
b1c44de49c36d63e36b97e92454b023ca5bd940c373459cd545803eaf331f900
-
SHA512
575a8258cd93bfacc37a28464d115ac5746f0515097fc8742bf0064399d93b52587160977af518298f2a9a4a10543f462917bfe29399e032f775961698072be8
-
SSDEEP
24576:1bKdVyx5LayYY3jEJCnRVVC5HLdeyaUE982LtJTAWyIywFvC98Zx:1bAIx5jJj/RVVC5HLYE2097wpCWZx
Score1/10 -
-
-
Target
Client-built.exe
-
Size
3.1MB
-
MD5
1e48869d1ce254c1aba0e61aedcdba8e
-
SHA1
cf79b1e78d9e1616208e653c4df4eef3b9f7360b
-
SHA256
ca182b6ce56a01a69122b24469fe5ad78e0cda78caeb49e5a814e2ac5774a10a
-
SHA512
fc6469a2297258cd9723f2d6c795e78c5b065ed709384bb18fe0fb8255cb2760e0633ec2683652ef88abd87ac21ef1d31eee3fd35e64f464d4da0c205fdcb343
-
SSDEEP
49152:7vilL26AaNeWgPhlmVqvMQ7XSKeQ03far7ToGddTHHB72eh2NT:7vaL26AaNeWgPhlmVqkQ7XSKu3Y
-
Quasar payload
-
Executes dropped EXE
-