File name: | SubSeven S.A.T 1.0.7.rar |
Full analysis: | https://app.any.run/tasks/9185cc1b-e527-4a0b-9964-6a089e8d236c |
Verdict: | Malicious activity |
Threats: | Quasar is a very popular RAT in the world thanks to its code being available in open-source. This malware can be used to control the victim’s computer remotely. |
Analysis date: | March 10, 2019, 19:03:11 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-rar |
File info: | RAR archive data, v5 |
MD5: | B85AEA526843A6CCB23D8A25E2859095 |
SHA1: | 656F8A2D9F95D199EBBD6EC7C695590816A05069 |
SHA256: | 39CF91175D8AB9B6DB693FBDDD845ADE6AD14EF5BFC5432DBE92CC5971CEFCEE |
SSDEEP: | 6144:oMNm6dAruZW6m4uo1WYBkCk9hrHcKjEtZSLKTE8Lr/4JwjNpLrQlqcS5OmP:o4m6OHSkCk3vjEtcOThLb4ANpLTBOmP |
.rar | | | RAR compressed archive (v5.0) (61.5) |
---|---|---|
.rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2696 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\SubSeven S.A.T 1.0.7.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
3016 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2696.12905\SubSeven S.A.T 1.0.7\SubSeven S.A.T 1.0.7.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2696.12905\SubSeven S.A.T 1.0.7\SubSeven S.A.T 1.0.7.exe | WinRAR.exe | ||||||||||||
User: admin Company: SubSeven Inc. Integrity Level: MEDIUM Description: SubSeven S.A.T 1.0.7 Exit code: 0 Version: 1.0.7 Modules
| |||||||||||||||
3796 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\cnetindependent.rtf" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Version: 14.0.6024.1000 Modules
|
(PID) Process: | (2696) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (2696) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (2696) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2696) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\SubSeven S.A.T 1.0.7.rar | |||
(PID) Process: | (2696) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (2696) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (2696) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (2696) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (2696) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
(PID) Process: | (2696) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3796 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVR31A0.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2696 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2696.12905\SubSeven S.A.T 1.0.7\Configuration\FileSearcher.ini | text | |
MD5:075AE3D2FC31640504F814F60E5EF713 | SHA256:17EB3C0168D0D7B21EDE5481150F17233427D89833EC121B4DBC4FB96CFAB71E | |||
3016 | SubSeven S.A.T 1.0.7.exe | C:\Users\admin\AppData\Local\Temp\4147af6d-4916-4fc1-9485-6a1753c51244_ccookies.txt | text | |
MD5:BF4671EB8331ACB10ED1162394DAB2A4 | SHA256:80E4C23E8B7200F1F75CE0DEAEE3B90F62FB458226231AED5AEFC1443E07C832 | |||
2696 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2696.12905\SubSeven S.A.T 1.0.7\Configuration\networkcontrol.ini | text | |
MD5:7E9F5A0E02F7B2B8654CABA1364A01B3 | SHA256:2A4B016BB7792CDB46BDC0075BCC0EE846046204BC1A87455B7BA9266B9CCC58 | |||
3796 | WINWORD.EXE | C:\Users\admin\Desktop\~$etindependent.rtf | pgc | |
MD5:16161600B1B54678FEF26020358EEC9E | SHA256:821F14B0030610CA1C780D0A7B9CDB40AFF1459618C1EC64309A464AF4593168 | |||
2696 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2696.12905\SubSeven S.A.T 1.0.7\Configuration\settings.ini | text | |
MD5:E6CEE1AAE2E0FADF069888784E9207A9 | SHA256:F891459C922E178C9EF398474160654C90B6A9FFC4DD3B148BA18FEFFB664F5F | |||
3796 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dat | text | |
MD5:27388BD434655F67141A8B2086FEB81D | SHA256:74B09EDE851AEFF4F4214A17981974BE6BE01CBF233D685136736F6A039B5787 | |||
3796 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\cnetindependent.rtf.LNK | lnk | |
MD5:873A3783FA06D76D78EC8A68AB9C45A1 | SHA256:A671757DA00A259746EFC687BB99B47E32F6F3491D9DE481FA66E2EFFC9F6134 | |||
2696 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2696.12905\SubSeven S.A.T 1.0.7\SubSeven S.A.T 1.0.7.exe | executable | |
MD5:B650ECA967D91F682B8690B9AB5C287A | SHA256:21C0829B0BFAB46113D6252BEDF883CFFDCD6D87789A76056127784F5EFF3762 | |||
3016 | SubSeven S.A.T 1.0.7.exe | C:\Users\admin\AppData\Local\Temp\e6f3475a-6185-4267-83f6-71b58a7d05c7_chrome.txt | text | |
MD5:A416BE74FF10403242D959EE6A3B01E2 | SHA256:82B5238C970BADF9EFD8B3343CA88E183412541AAEB43B4CDF522990351335C0 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3016 | SubSeven S.A.T 1.0.7.exe | GET | 301 | 104.31.76.103:80 | http://browserloot.rokey.xyz/api/get-ip.php | US | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3016 | SubSeven S.A.T 1.0.7.exe | 104.31.76.103:443 | browserloot.rokey.xyz | Cloudflare Inc | US | shared |
3016 | SubSeven S.A.T 1.0.7.exe | 104.31.77.103:443 | browserloot.rokey.xyz | Cloudflare Inc | US | shared |
3016 | SubSeven S.A.T 1.0.7.exe | 104.31.76.103:80 | browserloot.rokey.xyz | Cloudflare Inc | US | shared |
Domain | IP | Reputation |
---|---|---|
browserloot.rokey.xyz |
| malicious |
rokey.xyz |
| malicious |
PID | Process | Class | Message |
---|---|---|---|
— | — | A Network Trojan was detected | MALWARE [PTsecurity] BrowserLoot Stealer |
— | — | A Network Trojan was detected | MALWARE [PTsecurity] BrowserLoot Stealer Connection |