Analysis
-
max time kernel
152s -
max time network
153s -
platform
windows10-2004_x64 -
resource
win10v2004-20240226-en -
resource tags
arch:x64arch:x86image:win10v2004-20240226-enlocale:en-usos:windows10-2004-x64system -
submitted
01-07-2024 02:32
General
-
Target
Spoofer.exe
-
Size
3.1MB
-
MD5
751f5155537238c34bf0b718cbcbfec3
-
SHA1
da8832e49c287fda15326f88fb8909f5e5c8406e
-
SHA256
87a7aa13bc4864f4f113a0e88f93207d201504df57e486a5a31704339a0ceabd
-
SHA512
8791f01319cebfb2fee868de916689f3926c7af5152df44738f2ccededb1a5a02d751e4df1fd5b9e777b3e829a00f7f22a2a2bef5f17fc91186205066e0c81f3
-
SSDEEP
49152:Svht62XlaSFNWPjljiFa2RoUYIEVFAnpvj7LoJd5THHB72eh2NT:SvL62XlaSFNWPjljiFXRoUYI9n5
Malware Config
Extracted
quasar
1.4.1
Spoofer
192.168.0.105:2909
e7d81d52-e002-4d4a-826e-4f612340cec1
-
encryption_key
CBD82136C14646252528D79E6104B3979DC09D52
-
install_name
Client.exe
-
log_directory
Logs
-
reconnect_delay
3000
-
startup_key
update
-
subdirectory
SubDir
Signatures
-
Quasar payload 2 IoCs
Processes:
resource yara_rule behavioral1/memory/1444-1-0x0000000000AD0000-0x0000000000DF4000-memory.dmp family_quasar C:\Users\Admin\AppData\Roaming\SubDir\Client.exe family_quasar -
Executes dropped EXE 1 IoCs
Processes:
Client.exepid process 2248 Client.exe -
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Checks SCSI registry key(s) 3 TTPs 3 IoCs
SCSI information is often read in order to detect sandboxing environments.
Processes:
taskmgr.exedescription ioc process Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Enum\SCSI\Disk&Ven_DADY&Prod_HARDDISK\4&215468a5&0&000000\FriendlyName taskmgr.exe Key opened \REGISTRY\MACHINE\SYSTEM\ControlSet001\Enum\SCSI\Disk&Ven_DADY&Prod_HARDDISK\4&215468a5&0&000000 taskmgr.exe Key opened \REGISTRY\MACHINE\SYSTEM\ControlSet001\Enum\SCSI\Disk&Ven_DADY&Prod_HARDDISK\4&215468a5&0&000000\Properties\{b725f130-47ef-101a-a5f1-02608c9eebac}\000A taskmgr.exe -
Modifies registry class 1 IoCs
Processes:
taskmgr.exedescription ioc process Key created \REGISTRY\USER\S-1-5-21-3808065738-1666277613-1125846146-1000_Classes\Local Settings taskmgr.exe -
Scheduled Task/Job: Scheduled Task 1 TTPs 2 IoCs
Schtasks is often used by malware for persistence or to perform post-infection execution.
Processes:
schtasks.exeschtasks.exepid process 2128 schtasks.exe 4676 schtasks.exe -
Suspicious behavior: EnumeratesProcesses 64 IoCs
Processes:
taskmgr.exepid process 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe -
Suspicious use of AdjustPrivilegeToken 5 IoCs
Processes:
Spoofer.exeClient.exetaskmgr.exedescription pid process Token: SeDebugPrivilege 1444 Spoofer.exe Token: SeDebugPrivilege 2248 Client.exe Token: SeDebugPrivilege 1860 taskmgr.exe Token: SeSystemProfilePrivilege 1860 taskmgr.exe Token: SeCreateGlobalPrivilege 1860 taskmgr.exe -
Suspicious use of FindShellTrayWindow 64 IoCs
Processes:
Client.exetaskmgr.exepid process 2248 Client.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe -
Suspicious use of SendNotifyMessage 64 IoCs
Processes:
Client.exetaskmgr.exepid process 2248 Client.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe 1860 taskmgr.exe -
Suspicious use of SetWindowsHookEx 1 IoCs
Processes:
Client.exepid process 2248 Client.exe -
Suspicious use of WriteProcessMemory 6 IoCs
Processes:
Spoofer.exeClient.exedescription pid process target process PID 1444 wrote to memory of 2128 1444 Spoofer.exe schtasks.exe PID 1444 wrote to memory of 2128 1444 Spoofer.exe schtasks.exe PID 1444 wrote to memory of 2248 1444 Spoofer.exe Client.exe PID 1444 wrote to memory of 2248 1444 Spoofer.exe Client.exe PID 2248 wrote to memory of 4676 2248 Client.exe schtasks.exe PID 2248 wrote to memory of 4676 2248 Client.exe schtasks.exe -
Uses Task Scheduler COM API 1 TTPs
The Task Scheduler COM API can be used to schedule applications to run on boot or at set times.
Processes
-
C:\Users\Admin\AppData\Local\Temp\Spoofer.exe"C:\Users\Admin\AppData\Local\Temp\Spoofer.exe"1⤵
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Windows\SYSTEM32\schtasks.exe"schtasks" /create /tn "update" /sc ONLOGON /tr "C:\Users\Admin\AppData\Roaming\SubDir\Client.exe" /rl HIGHEST /f2⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Users\Admin\AppData\Roaming\SubDir\Client.exe"C:\Users\Admin\AppData\Roaming\SubDir\Client.exe"2⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
- Suspicious use of SetWindowsHookEx
- Suspicious use of WriteProcessMemory
-
C:\Windows\SYSTEM32\schtasks.exe"schtasks" /create /tn "update" /sc ONLOGON /tr "C:\Users\Admin\AppData\Roaming\SubDir\Client.exe" /rl HIGHEST /f3⤵
- Scheduled Task/Job: Scheduled Task
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --mojo-platform-channel-handle=4156 --field-trial-handle=2180,i,12780723798465539942,12010519452607841069,262144 --variations-seed-version /prefetch:81⤵
-
C:\Windows\system32\taskmgr.exe"C:\Windows\system32\taskmgr.exe" /41⤵
- Checks SCSI registry key(s)
- Modifies registry class
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
-
C:\Windows\System32\rundll32.exeC:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding1⤵
-
C:\Windows\System32\_iyiwy.exe"C:\Windows\System32\_iyiwy.exe"1⤵
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Roaming\SubDir\Client.exeFilesize
3.1MB
MD5751f5155537238c34bf0b718cbcbfec3
SHA1da8832e49c287fda15326f88fb8909f5e5c8406e
SHA25687a7aa13bc4864f4f113a0e88f93207d201504df57e486a5a31704339a0ceabd
SHA5128791f01319cebfb2fee868de916689f3926c7af5152df44738f2ccededb1a5a02d751e4df1fd5b9e777b3e829a00f7f22a2a2bef5f17fc91186205066e0c81f3
-
memory/1444-10-0x00007FFAE3680000-0x00007FFAE4141000-memory.dmpFilesize
10.8MB
-
memory/1444-1-0x0000000000AD0000-0x0000000000DF4000-memory.dmpFilesize
3.1MB
-
memory/1444-2-0x00007FFAE3680000-0x00007FFAE4141000-memory.dmpFilesize
10.8MB
-
memory/1444-0-0x00007FFAE3683000-0x00007FFAE3685000-memory.dmpFilesize
8KB
-
memory/1860-28-0x00000257864F0000-0x00000257864F1000-memory.dmpFilesize
4KB
-
memory/1860-25-0x00000257864F0000-0x00000257864F1000-memory.dmpFilesize
4KB
-
memory/1860-23-0x00000257864F0000-0x00000257864F1000-memory.dmpFilesize
4KB
-
memory/1860-22-0x00000257864F0000-0x00000257864F1000-memory.dmpFilesize
4KB
-
memory/1860-26-0x00000257864F0000-0x00000257864F1000-memory.dmpFilesize
4KB
-
memory/1860-27-0x00000257864F0000-0x00000257864F1000-memory.dmpFilesize
4KB
-
memory/1860-18-0x00000257864F0000-0x00000257864F1000-memory.dmpFilesize
4KB
-
memory/1860-17-0x00000257864F0000-0x00000257864F1000-memory.dmpFilesize
4KB
-
memory/1860-16-0x00000257864F0000-0x00000257864F1000-memory.dmpFilesize
4KB
-
memory/1860-24-0x00000257864F0000-0x00000257864F1000-memory.dmpFilesize
4KB
-
memory/2248-9-0x00007FFAE3680000-0x00007FFAE4141000-memory.dmpFilesize
10.8MB
-
memory/2248-15-0x00007FFAE3680000-0x00007FFAE4141000-memory.dmpFilesize
10.8MB
-
memory/2248-14-0x00007FFAE3680000-0x00007FFAE4141000-memory.dmpFilesize
10.8MB
-
memory/2248-11-0x00007FFAE3680000-0x00007FFAE4141000-memory.dmpFilesize
10.8MB
-
memory/2248-13-0x000000001C3B0000-0x000000001C462000-memory.dmpFilesize
712KB
-
memory/2248-12-0x000000001C2A0000-0x000000001C2F0000-memory.dmpFilesize
320KB
-
memory/2248-29-0x000000001CCE0000-0x000000001D208000-memory.dmpFilesize
5.2MB