General

  • Target

    https://pcapi-server.com/download/Zhuriken.exe

  • Sample

    240703-qyknxsyhrb

Malware Config

Extracted

Family

quasar

Version

1.4.1

Botnet

Office04

C2

91.92.253.215:4782

Mutex

4304b988-116c-4522-ab83-7f9ad875f60f

Attributes
  • encryption_key

    A6B8B9B9B02FC86103A59CE003D7B3B45DAF8550

  • install_name

    Client.exe

  • log_directory

    ZhurikenLogs

  • reconnect_delay

    3000

  • startup_key

    Zhuriken Client Startup

  • subdirectory

    SubDir

Targets

MITRE ATT&CK Matrix ATT&CK v13

Execution

Command and Scripting Interpreter

1
T1059

PowerShell

1
T1059.001

Privilege Escalation

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Defense Evasion

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Impair Defenses

1
T1562

Disable or Modify Tools

1
T1562.001

Modify Registry

2
T1112

Discovery

System Information Discovery

2
T1082

Query Registry

1
T1012

Tasks