Malicious
Malicious

f6a75a1b8bf8df20fd53d7d80b421881

PE Executable
|
MD5: f6a75a1b8bf8df20fd53d7d80b421881
|
Size: 376.84 KB
|
application/x-dosexec


Print
Infection Chain
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
f6a75a1b8bf8df20fd53d7d80b421881
Sha1
00a9a7cfc530d71635f882541ca92645807045d0
Sha256
5d5ca00a6798d7183127db8eb8ef1d230b7cd2fd41002de4beea0c650e9bb714
Sha384
9a88164625c97a90851750482a8e89ac860a5bff4c87f900079f72acfdc3ba0f6480b55729c76de392ed70aec5d94dec
Sha512
1f9ab9439e3765827473195693013737920ba6704eed68ded5ae5f698a3829719ceba89a4dc382bc8b7d64944d792ae325fc549c6dbde6b636cf3a11fca839c6
SSDeep
6144:h7NHXf500MxKlLUWLD3bwMgdlQF2A7hUYPyVbJe:1d50alLVMnlK2A7qYPGbJe
TLSH
AA848C1333A8D63BD1BE577AF53606044BB1D447BA16F38F9A5896B82C133868D913B3

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
.Net Resources
xClient.Properties.Resources.resources
information
[NBF]root.Data
[NBF]root.Data-preview.png
Malware Configuration - QuasarRAT config.
Config. Field
Value
Conf. AES-Salt

BF-EB-1E-56-FB-CD-97-3B-B2-19-02-24-30-A5-78-43-00-3D-56-44-D2-1E-62-B9-D4-F1-80-E7-E6-C3-39-41

Conf. AES-Key

JTis9uZa3y2AQVXE5OLV

Version

1.3.0.0

Port

1604

Host

85.121.4.92

ReconnectDelay

3000

Key

1WvgEMPjdwfqIMeM9MclyQ==

AuthKey

NcFtjbDOcsw7Evd3coMC0y4koy/SRZGydhNmno81ZOWOvdfg7sv0Cj5ad2ROUfX4QMscAIjYJdjrrs41+qcQwg==

SubDirectory

SubDir

InstallName

Client.exe

Install

1

Startup

0

Mutex

QSR_MUTEX_A0MQsC

StartupKey

Quasar Client St

HideFile

0

EnableLogger

1

Tag

Office04

LogDirectory

Logs

HideLogDirectory

0

HideLogSubdirectory

0

Informations
Name
Value
Info

PE Detect: PeReader FAIL, AsmResolver Mapped OK

Info

Remap: Mapped -> FileLayout (RAM only) as [Rebuild from dump]_27078b2f.exe

Module Name

Client.exe

Full Name

Client.exe

EntryPoint

System.Void 鉥뷒䔑�ݝꯙ늴ﮬ骇毩奄笳᫢::Main(System.String[])

Scope Name

Client.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Client

Assembly Version

1.3.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0,Profile=Client

Total Strings

896

Main Method

System.Void 鉥뷒䔑�ݝꯙ늴ﮬ骇毩奄笳᫢::Main(System.String[])

Main IL Instruction Count

19

Main IL

call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) call System.AppDomain System.AppDomain::get_CurrentDomain() ldnull <null> ldftn System.Void 鉥뷒䔑�ݝꯙ늴ﮬ骇毩奄笳᫢::႕Ⓘ悩ጼ䙳塢懶眎护๯�緔杰쎒揊徥ꗢ�㊫(System.Object,System.UnhandledExceptionEventArgs) newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr) callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler) call System.Boolean 呜魠溊甅锧괫⩭㝰㛤⵺Ꮣ콂竸끓�∣㰨�㨚::䂋͊余䲇㰹핧쭖翉焵᯶烪陶酄輗臨ꦴ‡㯆�() brfalse.s IL_0040: call System.Void 鉥뷒䔑�ݝꯙ늴ﮬ骇毩奄笳᫢::腡롉鑉�烐숚걬麤㮜縉拄⟬㏻竽ᗘ뇂鍭ࣹ() call System.Boolean 鉥뷒䔑�ݝꯙ늴ﮬ骇毩奄笳᫢::贜뻔脟ࣄ묫뚧讘持ꬻ폫渡쒳툙긐㯈梾橁() brfalse.s IL_0040: call System.Void 鉥뷒䔑�ݝꯙ늴ﮬ骇毩奄笳᫢::腡롉鑉�烐숚걬麤㮜縉拄⟬㏻竽ᗘ뇂鍭ࣹ() call System.Boolean 爂ぉ숅廀ᥛ鯒鵙२ႇ랢ⵕᛆᔩ痾߈㢕ﴣ✢암::get_Exiting() brtrue.s IL_0040: call System.Void 鉥뷒䔑�ݝꯙ늴ﮬ骇毩奄笳᫢::腡롉鑉�烐숚걬麤㮜縉拄⟬㏻竽ᗘ뇂鍭ࣹ() ldsfld 爂ぉ숅廀ᥛ鯒鵙२ႇ랢ⵕᛆᔩ痾߈㢕ﴣ✢암 鉥뷒䔑�ݝꯙ늴ﮬ骇毩奄笳᫢::糊鮙徰댴龰蹘�薺魈༾ꡎ⤈⦝ີ钰ჵ曵 callvirt System.Void 爂ぉ숅廀ᥛ鯒鵙२ႇ랢ⵕᛆᔩ痾߈㢕ﴣ✢암::푅珮ᐖᇂ鶷膧㎾菔崟脿⦑�㻇ⵉ榑左ฦ쬙() call System.Void 鉥뷒䔑�ݝꯙ늴ﮬ骇毩奄笳᫢::腡롉鑉�烐숚걬麤㮜縉拄⟬㏻竽ᗘ뇂鍭ࣹ() call System.Void 鉥뷒䔑�ݝꯙ늴ﮬ骇毩奄笳᫢::î멚왰沟㭡怉ᨡ࿇뜺⫰接ৱ튪쁵梻骸㜾ₚ臣() ret <null>

Module Name

Client.exe

Full Name

Client.exe

EntryPoint

System.Void 鉥뷒䔑�ݝꯙ늴ﮬ骇毩奄笳᫢::Main(System.String[])

Scope Name

Client.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Client

Assembly Version

1.3.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0,Profile=Client

Total Strings

896

Main Method

System.Void 鉥뷒䔑�ݝꯙ늴ﮬ骇毩奄笳᫢::Main(System.String[])

Main IL Instruction Count

19

Main IL

call System.Void System.Windows.Forms.Application::EnableVisualStyles() ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) call System.AppDomain System.AppDomain::get_CurrentDomain() ldnull <null> ldftn System.Void 鉥뷒䔑�ݝꯙ늴ﮬ骇毩奄笳᫢::႕Ⓘ悩ጼ䙳塢懶眎护๯�緔杰쎒揊徥ꗢ�㊫(System.Object,System.UnhandledExceptionEventArgs) newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr) callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler) call System.Boolean 呜魠溊甅锧괫⩭㝰㛤⵺Ꮣ콂竸끓�∣㰨�㨚::䂋͊余䲇㰹핧쭖翉焵᯶烪陶酄輗臨ꦴ‡㯆�() brfalse.s IL_0040: call System.Void 鉥뷒䔑�ݝꯙ늴ﮬ骇毩奄笳᫢::腡롉鑉�烐숚걬麤㮜縉拄⟬㏻竽ᗘ뇂鍭ࣹ() call System.Boolean 鉥뷒䔑�ݝꯙ늴ﮬ骇毩奄笳᫢::贜뻔脟ࣄ묫뚧讘持ꬻ폫渡쒳툙긐㯈梾橁() brfalse.s IL_0040: call System.Void 鉥뷒䔑�ݝꯙ늴ﮬ骇毩奄笳᫢::腡롉鑉�烐숚걬麤㮜縉拄⟬㏻竽ᗘ뇂鍭ࣹ() call System.Boolean 爂ぉ숅廀ᥛ鯒鵙२ႇ랢ⵕᛆᔩ痾߈㢕ﴣ✢암::get_Exiting() brtrue.s IL_0040: call System.Void 鉥뷒䔑�ݝꯙ늴ﮬ骇毩奄笳᫢::腡롉鑉�烐숚걬麤㮜縉拄⟬㏻竽ᗘ뇂鍭ࣹ() ldsfld 爂ぉ숅廀ᥛ鯒鵙२ႇ랢ⵕᛆᔩ痾߈㢕ﴣ✢암 鉥뷒䔑�ݝꯙ늴ﮬ骇毩奄笳᫢::糊鮙徰댴龰蹘�薺魈༾ꡎ⤈⦝ີ钰ჵ曵 callvirt System.Void 爂ぉ숅廀ᥛ鯒鵙२ႇ랢ⵕᛆᔩ痾߈㢕ﴣ✢암::푅珮ᐖᇂ鶷膧㎾菔崟脿⦑�㻇ⵉ榑左ฦ쬙() call System.Void 鉥뷒䔑�ݝꯙ늴ﮬ骇毩奄笳᫢::腡롉鑉�烐숚걬麤㮜縉拄⟬㏻竽ᗘ뇂鍭ࣹ() call System.Void 鉥뷒䔑�ݝꯙ늴ﮬ骇毩奄笳᫢::î멚왰沟㭡怉ᨡ࿇뜺⫰接ৱ튪쁵梻骸㜾ₚ臣() ret <null>

Artefacts
Name
Value
CnC

85.121.4.92

Port

1604

PE Layout

MemoryMapped (process dump suspected)

CnC

85.121.4.92

Port

1604

PE Layout

MemoryMapped (process dump suspected)

f6a75a1b8bf8df20fd53d7d80b421881 (376.84 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙