General

  • Target

    Client-built2.exe

  • Size

    342KB

  • Sample

    240703-3wg68svapf

  • MD5

    13068ff1db0fbb26129b02afe8567572

  • SHA1

    0fe5b876286049d09c1f4dbf0259c0dac94f1a8a

  • SHA256

    12dc2baf687f02a7df0fed338cb08d23f36a4a603ca5f79c4ac4e56a5ba513f8

  • SHA512

    939594001ac03b07e242cbf9b98067e25eab2684d68b489d702032bfaf941f9ce37d5514cef6d57d856f1e97caf73fa666de6ee1f5604fc95c7ba8169c4cc9a3

  • SSDEEP

    6144:f8CnG6AjVvEdTn4b12eBNwktELSSvllMr2aZn55e45N7m6NiQ+1cuAIfu:f8BIdUbjNvpXr2aTdm6NiXc7f

Malware Config

Targets

    • Target

      Client-built2.exe

    • Size

      342KB

    • MD5

      13068ff1db0fbb26129b02afe8567572

    • SHA1

      0fe5b876286049d09c1f4dbf0259c0dac94f1a8a

    • SHA256

      12dc2baf687f02a7df0fed338cb08d23f36a4a603ca5f79c4ac4e56a5ba513f8

    • SHA512

      939594001ac03b07e242cbf9b98067e25eab2684d68b489d702032bfaf941f9ce37d5514cef6d57d856f1e97caf73fa666de6ee1f5604fc95c7ba8169c4cc9a3

    • SSDEEP

      6144:f8CnG6AjVvEdTn4b12eBNwktELSSvllMr2aZn55e45N7m6NiQ+1cuAIfu:f8BIdUbjNvpXr2aTdm6NiXc7f

    • Quasar RAT

      Quasar is an open source Remote Access Tool.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Adds Run key to start application

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

2
T1012

System Information Discovery

2
T1082

Tasks