General
-
Target
svchost.bat
-
Size
607KB
-
Sample
240702-p9jekaxeln
-
MD5
cdd288e92953495d53b0b28b30d135a6
-
SHA1
a7bd0567125f27171f60322bdc29c1bb8b8fcd25
-
SHA256
4c4667a8d86e4369c1b7e16e38f86292b2ffcbfe506613899291a52f15f0128a
-
SHA512
2ed4a854ddc83d6d32ce7948740e0474b3794d054c325d1b71af7cf17c54460b200a2a9126b02001eba8f1e5bb105ac8e01c3ca1c91da093e4422fa53dfbf173
-
SSDEEP
12288:Ph2Dh0mFsRXQ7ZpK1b4Bdbi6EGv8/K9yxnQ3nzvc7l87wrJJ3HMU:Pujsxb4B0KAxnww7y7+v
Static task
static1
Malware Config
Extracted
quasar
-
reconnect_delay
3000
Extracted
xworm
super-nearest.gl.at.ply.gg:17835
best-bird.gl.at.ply.gg:27196
wiz.bounceme.net:6000
-
Install_directory
%ProgramData%
Extracted
asyncrat
Default
finally-grande.gl.at.ply.gg:25844
-
delay
1
-
install
false
-
install_folder
%AppData%
Extracted
quasar
3.1.5
Slave
stop-largely.gl.at.ply.gg:27116
$Sxr-kl1r656AGsPQksTmi8
-
encryption_key
WyBm1iVkHZmEnGPMAZWV
-
install_name
$phantom.exe
-
log_directory
Logs
-
reconnect_delay
3000
-
startup_key
$phantomSTARTUP~MSF
-
subdirectory
$phantom
Targets
-
-
Target
svchost.bat
-
Size
607KB
-
MD5
cdd288e92953495d53b0b28b30d135a6
-
SHA1
a7bd0567125f27171f60322bdc29c1bb8b8fcd25
-
SHA256
4c4667a8d86e4369c1b7e16e38f86292b2ffcbfe506613899291a52f15f0128a
-
SHA512
2ed4a854ddc83d6d32ce7948740e0474b3794d054c325d1b71af7cf17c54460b200a2a9126b02001eba8f1e5bb105ac8e01c3ca1c91da093e4422fa53dfbf173
-
SSDEEP
12288:Ph2Dh0mFsRXQ7ZpK1b4Bdbi6EGv8/K9yxnQ3nzvc7l87wrJJ3HMU:Pujsxb4B0KAxnww7y7+v
-
Detect Xworm Payload
-
Quasar payload
-
Async RAT payload
-
Blocklisted process makes network request
-
Checks computer location settings
Looks up country code configured in the registry, likely geofence.
-
Drops startup file
-
Executes dropped EXE
-
Adds Run key to start application
-
Looks up external IP address via web service
Uses a legitimate IP lookup service to find the infected system's external IP.
-
MITRE ATT&CK Matrix ATT&CK v13
Execution
Command and Scripting Interpreter
1PowerShell
1Scheduled Task/Job
1Scheduled Task
1Persistence
Boot or Logon Autostart Execution
1Registry Run Keys / Startup Folder
1Scheduled Task/Job
1Scheduled Task
1