General

  • Target

    Client-built.exe

  • Size

    3.1MB

  • Sample

    240630-tqt46szhlf

  • MD5

    acae78b76f4b990b86e2d2d5edfbb6fe

  • SHA1

    0407bc802c64787ffd2baf35f6ef6c186e88d1dc

  • SHA256

    afaf1fafdbbd222021f2d6dc870e4026866a2be055654207be312d6d9cbf3bf4

  • SHA512

    8ff3124fa36c76ee7da622cf6faa6e992369dd6211e9808896afb32b677dadbbf65ed36748c8b7edfd0d01a706b3e38e293053f10e2d983017061f82fc426ee3

  • SSDEEP

    49152:SvnI22SsaNYfdPBldt698dBcjHBuRJ6dbR3LoGdKITHHB72eh2NT:SvI22SsaNYfdPBldt6+dBcjHBuRJ6v6

Malware Config

Extracted

Family

quasar

Version

1.4.1

Botnet

Office04

C2

192.168.1.150:4782

Mutex

adc301f6-35ca-4636-b286-ad2aef63f877

Attributes
  • encryption_key

    54B7AB1A151267275EF24D335CE7E3B6ABDDC53E

  • install_name

    Client.exe

  • log_directory

    Logs

  • reconnect_delay

    3000

  • startup_key

    Microsoft Launcher Task Manager

  • subdirectory

    SubDir

Targets

    • Target

      Client-built.exe

    • Size

      3.1MB

    • MD5

      acae78b76f4b990b86e2d2d5edfbb6fe

    • SHA1

      0407bc802c64787ffd2baf35f6ef6c186e88d1dc

    • SHA256

      afaf1fafdbbd222021f2d6dc870e4026866a2be055654207be312d6d9cbf3bf4

    • SHA512

      8ff3124fa36c76ee7da622cf6faa6e992369dd6211e9808896afb32b677dadbbf65ed36748c8b7edfd0d01a706b3e38e293053f10e2d983017061f82fc426ee3

    • SSDEEP

      49152:SvnI22SsaNYfdPBldt698dBcjHBuRJ6dbR3LoGdKITHHB72eh2NT:SvI22SsaNYfdPBldt6+dBcjHBuRJ6v6

    • Quasar RAT

      Quasar is an open source Remote Access Tool.

    • Quasar payload

    • Executes dropped EXE

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Persistence

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Privilege Escalation

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Discovery

System Information Discovery

2
T1082

Query Registry

2
T1012

Tasks