download:

/Cryakl/Ultimate-RAT-Collection/raw/refs/heads/main/Pulsar/Pulsaar%20v6.7/Pulsaar.7z

Full analysis: https://app.any.run/tasks/b054d9ca-6caa-4aea-b4bf-3eb181bf621a
Verdict: Malicious activity
Threats:

Pulsar RAT is a derivative of Quasar RAT with extensive functionality including keylogging, cryptocurrency wallet clipping, credential theft, file management, remote shell execution, and data exfiltration capabilities. As a modular, open-source remote administration tool designed for Windows systems, Pulsar introduces significant enhancements over its predecessor.

Analysis date: June 02, 2026, 10:26:04
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
pulsar
rat
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

8293DFD192D9244E19A16B5F22178228

SHA1:

AFD708A1C693E222729068BA59128791345C2795

SHA256:

1446EC71637D8D3573D8F09E9D65C86622F338AB1B6A0ED20D68BA246D4C7135

SSDEEP:

98304:/2u0AVD/0PhHv7/n5w0vOFX1Uvy0Ta/I0f1rN85jA145iqQcdU4+6X61b7p9sslu:fBTsvVRpjRJhlBR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • PULSAR has been detected (YARA)

      • Pulsaar.exe (PID: 6592)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • WinRAR.exe (PID: 5876)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 5876)
    • Manual execution by a user

      • Client.exe (PID: 5160)
      • Pulsaar.exe (PID: 6592)
    • Reads the computer name

      • Client.exe (PID: 5160)
      • Pulsaar.exe (PID: 6592)
    • Checks supported languages

      • Client.exe (PID: 5160)
      • Pulsaar.exe (PID: 6592)
    • Creates files or folders in the user directory

      • Pulsaar.exe (PID: 6592)
    • Disables trace logs

      • Pulsaar.exe (PID: 6592)
    • Reads Environment values

      • Client.exe (PID: 5160)
      • Pulsaar.exe (PID: 6592)
    • Reads the machine GUID from the registry

      • Client.exe (PID: 5160)
      • Pulsaar.exe (PID: 6592)
    • There is functionality for taking screenshot (YARA)

      • Pulsaar.exe (PID: 6592)
    • Reads product name

      • Pulsaar.exe (PID: 6592)
    • Create files in a temporary directory

      • Pulsaar.exe (PID: 6592)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.9)

EXIF

ZIP

FileVersion: 7z v0.04
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
157
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe slui.exe client.exe no specs #PULSAR pulsaar.exe

Process information

PID
CMD
Path
Indicators
Parent process
5160"C:\Users\admin\Desktop\Pulsaar\Client.exe" C:\Users\admin\Desktop\Pulsaar\Client.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Version:
1.6.6
Modules
Images
c:\users\admin\desktop\pulsaar\client.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
5876"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\Pulsaar.7zC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6592"C:\Users\admin\Desktop\Pulsaar\Pulsaar.exe" C:\Users\admin\Desktop\Pulsaar\Pulsaar.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Pulsar Server
Version:
1.6.6
Modules
Images
c:\users\admin\desktop\pulsaar\pulsaar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
8644C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
0
Read events
0
Write events
0
Delete events
0

Modification events

No data
Executable files
54
Suspicious files
2
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
5876WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb5876.11382\Pulsaar\client.binexecutable
MD5:DCD8EF4AA7BA67907DAA8F59D6CF218A
SHA256:8007B626AE378C35178F09531700BF7174891F34DD17C29399E74133447C2508
5876WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb5876.11382\Pulsaar\Profiles\Default.jsontext
MD5:1A6CC8AD64DB8D11E0B134D0E4ABF193
SHA256:27BC69535EECE4C9E8C0F14D761E351B6BE17BEB2C12632CA79B29A63AB257CC
5876WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb5876.11382\Pulsaar\AForge.dllexecutable
MD5:02C63F568E598AAD85DD401D7B26E82A
SHA256:966A474060A8ACA70C73BA09D0B6FE2353035961C7107B9003EF879C010FF8DA
5876WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb5876.11382\Pulsaar\blocked.jsontext
MD5:D751713988987E9331980363E24189CE
SHA256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
5876WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb5876.11382\Pulsaar\Pulsar.exe.configxml
MD5:1BD04B6D422191179D628FE6C7E21376
SHA256:5CD1B3ED19634B7354BB7177F2DB96C94EB9A4CE35C795F97D95473A91E94651
5876WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb5876.11382\Pulsaar\Pulsar.p12binary
MD5:17DAA2B7F48A952F0B94A2045B8108FC
SHA256:B07F769D8D5BC09F8CC0607AC22EF76F3F4E759F234D3102650BDC39D2AF0C6F
5876WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb5876.11382\Pulsaar\Pulsar.Common.Tests.dll.configxml
MD5:08CEE33645BB7A5253917E15183361F8
SHA256:D9036FB3790C06446D32B25C3D048F762C5BE30B3A3473BCF7FE35CD38443690
5876WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb5876.11382\Pulsaar\dnlib.dllexecutable
MD5:C087C70DEB98DB9D0B046D0A3D0E582A
SHA256:97EF5328D1D1703924C48D9CD1D45B7227FE3836E116DCDED623B6A0DBD52C23
5876WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb5876.11382\Pulsaar\PulsarStuff\autotasks.jsontext
MD5:D751713988987E9331980363E24189CE
SHA256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
5876WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb5876.11382\Pulsaar\Client.exeexecutable
MD5:DCD8EF4AA7BA67907DAA8F59D6CF218A
SHA256:8007B626AE378C35178F09531700BF7174891F34DD17C29399E74133447C2508
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
32
TCP/UDP connections
27
DNS requests
18
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
9108
svchost.exe
POST
400
40.126.32.134:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
204 b
whitelisted
9108
svchost.exe
POST
400
40.126.32.134:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
204 b
whitelisted
5276
MoUsoCoreWorker.exe
GET
304
48.209.133.15:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
9108
svchost.exe
POST
400
40.126.32.134:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
204 b
whitelisted
812
SIHClient.exe
GET
304
74.179.77.204:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
9108
svchost.exe
POST
400
40.126.32.134:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
204 b
whitelisted
7884
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
812
SIHClient.exe
GET
200
135.233.95.135:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
812
SIHClient.exe
GET
200
74.179.77.204:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
812
SIHClient.exe
GET
304
74.179.77.204:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
7884
svchost.exe
48.209.138.168:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
5276
MoUsoCoreWorker.exe
48.209.138.168:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
352
slui.exe
48.192.1.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3428
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
9108
svchost.exe
40.126.32.134:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
9108
svchost.exe
172.66.2.5:80
ocsp.digicert.com
CLOUDFLARENET
US
whitelisted
7884
svchost.exe
57.153.246.3:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7884
svchost.exe
23.216.77.28:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 48.209.138.168
  • 57.153.246.3
  • 48.209.133.15
  • 48.209.6.48
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.65
  • 128.24.231.64
whitelisted
google.com
  • 142.251.14.101
  • 142.251.14.100
  • 142.251.14.139
  • 142.251.14.113
  • 142.251.14.138
  • 142.251.14.102
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.32.134
  • 40.126.32.133
  • 20.190.160.20
  • 40.126.32.136
  • 20.190.160.5
  • 20.190.160.67
  • 20.190.160.128
  • 20.190.160.14
whitelisted
ocsp.digicert.com
  • 172.66.2.5
  • 162.159.142.9
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 23.52.181.212
whitelisted
api.github.com
  • 140.82.121.6
whitelisted
slscr.update.microsoft.com
  • 74.179.77.204
whitelisted

Threats

PID
Process
Class
Message
7884
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info