File name:

RtkAudUService64.exe

Full analysis: https://app.any.run/tasks/f0f937a8-d7c6-42b7-bee3-aafc1c3e50a9
Verdict: Malicious activity
Threats:

Quasar is a very popular RAT in the world thanks to its code being available in open-source. This malware can be used to control the victim’s computer remotely.

Analysis date: March 01, 2025, 21:49:30
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
quasar
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

B436CD6E40694322277B9094C082DC0D

SHA1:

91F5FF051D3EAF916065DDE80EB4389AA77BD4F8

SHA256:

485FFE0015067B6FBC703197EA46AE62D3CF0B70CB5C5A0A16B1E5C5DCE950D8

SSDEEP:

12288:qkNOxyX7at/REZcgc5LGPVg1hsW+gsxhO0PK5zKjvaEC/:r3atQc5KPVQ+gIhqzmiEY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • RtkAudUService64.exe (PID: 7412)
      • RtkAudUService64.exe (PID: 7440)
    • QUASAR has been detected (YARA)

      • RtkAudUService64.exe (PID: 7440)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • RtkAudUService64.exe (PID: 7412)
    • Starts itself from another location

      • RtkAudUService64.exe (PID: 7412)
    • Connects to unusual port

      • RtkAudUService64.exe (PID: 7440)
    • There is functionality for taking screenshot (YARA)

      • RtkAudUService64.exe (PID: 7440)
  • INFO

    • Checks supported languages

      • RtkAudUService64.exe (PID: 7412)
      • RtkAudUService64.exe (PID: 7440)
    • Reads the machine GUID from the registry

      • RtkAudUService64.exe (PID: 7412)
      • RtkAudUService64.exe (PID: 7440)
    • Reads the computer name

      • RtkAudUService64.exe (PID: 7412)
      • RtkAudUService64.exe (PID: 7440)
    • Creates files or folders in the user directory

      • RtkAudUService64.exe (PID: 7412)
    • Reads Environment values

      • RtkAudUService64.exe (PID: 7440)
    • Checks proxy server information

      • slui.exe (PID: 7784)
    • Reads the software policy settings

      • slui.exe (PID: 7784)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Quasar

(PID) Process(7440) RtkAudUService64.exe
Version1.4.1
C2 (3)127.0.0.1:32419
index-sustained.gl.at.ply.gg:32419
Sub_DirRealtek
Install_NameRtkAudUService64.exe
Mutexe2a36592-98df-46a9-812a-431d9a54e11a
StartupRealtek HD audio sulutions (RtkAudUService64.exe)
TagRealtek
LogDirLogs
SignaturePTeO04NOO+DVt723B29sUs35Xns7UU7cSWv4ThwRc/6p6KmvFA5AZIc2SHF9/zbK8jrYGnWir09+P/nHqjvPR1jDW4HJscgLbwDvP8T1CpTScRjSPeNjDPjj40hjPtqjF0YKZbjsYIv6BcSXFpBuXlfiuLpwqvtflSNSx29YCP+13B+yHt/mcHIWzwUNsR91DyzwIKRxt5YQkIBkoRHHI7mPbM57Kfeqo6fD6ELAFNebkuB7wNJ4YyChmYrkYr5rIhSXzbkRprSCPypR7VHZrYVl9KUG5djTovlMp0h2nFBK...
CertificateMIIFEzCCAvugAwIBAgIVAN3XDFsnpdiNWlIh9mYYMv9a386xMA0GCSqGSIb3DQEBDQUAMBUxEzARBgNVBAMMCk1vZCBTZXJ2ZXIwHhcNMjUwMjI2MDMzNDQ3WhcNMzUwMjI3MDMzNDQ3WjAVMRMwEQYDVQQDDApNb2QgU2VydmVyMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAgZ+MbNtC71L7CQ/nR7U3cEbq2mt8u7cKeI88ldJycbHv0kNFns/pmxks+crPbDun/fAqPH+aGU3s9TmuzVnG...
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (42.9)
.exe | Win32 EXE PECompact compressed (generic) (24.3)
.exe | Win64 Executable (generic) (16.1)
.scr | Windows screen saver (7.6)
.dll | Win32 Dynamic Link Library (generic) (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:02:28 02:13:43+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 1433600
InitializedDataSize: 3584
UninitializedDataSize: -
EntryPoint: 0x15feae
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.2.4.2
ProductVersionNumber: 1.2.4.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: Realtek
FileDescription: Realtek HD Audio Universal Service
FileVersion: 1.2.4.2
InternalName: Realtek audio
LegalCopyright: 2029
LegalTrademarks: Realtek
OriginalFileName: Realtek audio
ProductName: Realtek audio
ProductVersion: 1.2.4.0
AssemblyVersion: 1.2.4.0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
122
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start rtkauduservice64.exe #QUASAR rtkauduservice64.exe svchost.exe slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
7412"C:\Users\admin\Desktop\RtkAudUService64.exe" C:\Users\admin\Desktop\RtkAudUService64.exe
explorer.exe
User:
admin
Company:
Realtek
Integrity Level:
MEDIUM
Description:
Realtek HD Audio Universal Service
Exit code:
3
Version:
1.2.4.2
Modules
Images
c:\users\admin\desktop\rtkauduservice64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
7440"C:\Users\admin\AppData\Roaming\Realtek\RtkAudUService64.exe"C:\Users\admin\AppData\Roaming\Realtek\RtkAudUService64.exe
RtkAudUService64.exe
User:
admin
Company:
Realtek
Integrity Level:
MEDIUM
Description:
Realtek HD Audio Universal Service
Version:
1.2.4.2
Modules
Images
c:\users\admin\appdata\roaming\realtek\rtkauduservice64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Quasar
(PID) Process(7440) RtkAudUService64.exe
Version1.4.1
C2 (3)127.0.0.1:32419
index-sustained.gl.at.ply.gg:32419
Sub_DirRealtek
Install_NameRtkAudUService64.exe
Mutexe2a36592-98df-46a9-812a-431d9a54e11a
StartupRealtek HD audio sulutions (RtkAudUService64.exe)
TagRealtek
LogDirLogs
SignaturePTeO04NOO+DVt723B29sUs35Xns7UU7cSWv4ThwRc/6p6KmvFA5AZIc2SHF9/zbK8jrYGnWir09+P/nHqjvPR1jDW4HJscgLbwDvP8T1CpTScRjSPeNjDPjj40hjPtqjF0YKZbjsYIv6BcSXFpBuXlfiuLpwqvtflSNSx29YCP+13B+yHt/mcHIWzwUNsR91DyzwIKRxt5YQkIBkoRHHI7mPbM57Kfeqo6fD6ELAFNebkuB7wNJ4YyChmYrkYr5rIhSXzbkRprSCPypR7VHZrYVl9KUG5djTovlMp0h2nFBK...
CertificateMIIFEzCCAvugAwIBAgIVAN3XDFsnpdiNWlIh9mYYMv9a386xMA0GCSqGSIb3DQEBDQUAMBUxEzARBgNVBAMMCk1vZCBTZXJ2ZXIwHhcNMjUwMjI2MDMzNDQ3WhcNMzUwMjI3MDMzNDQ3WjAVMRMwEQYDVQQDDApNb2QgU2VydmVyMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAgZ+MbNtC71L7CQ/nR7U3cEbq2mt8u7cKeI88ldJycbHv0kNFns/pmxks+crPbDun/fAqPH+aGU3s9TmuzVnG...
7784C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
4 011
Read events
4 009
Write events
2
Delete events
0

Modification events

(PID) Process:(7440) RtkAudUService64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Realtek HD audio sulutions (RtkAudUService64.exe)
Value:
"C:\Users\admin\AppData\Roaming\Realtek\RtkAudUService64.exe"
(PID) Process:(7412) RtkAudUService64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Realtek HD audio sulutions (RtkAudUService64.exe)
Value:
"C:\Users\admin\AppData\Roaming\Realtek\RtkAudUService64.exe"
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
7412RtkAudUService64.exeC:\Users\admin\AppData\Roaming\Realtek\RtkAudUService64.exeexecutable
MD5:B436CD6E40694322277B9094C082DC0D
SHA256:485FFE0015067B6FBC703197EA46AE62D3CF0B70CB5C5A0A16B1E5C5DCE950D8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
22
DNS requests
4
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
POST
500
40.91.76.224:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
unknown
xml
512 b
whitelisted
POST
500
40.91.76.224:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
unknown
xml
512 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
7440
RtkAudUService64.exe
147.185.221.26:32419
index-sustained.gl.at.ply.gg
PLAYIT-GG
US
malicious
4652
slui.exe
40.91.76.224:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7784
slui.exe
40.91.76.224:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
google.com
  • 172.217.16.206
whitelisted
index-sustained.gl.at.ply.gg
  • 147.185.221.26
malicious
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

PID
Process
Class
Message
A Network Trojan was detected
MALWARE [ANY.RUN] Suspected domain Associated with Malware Distribution (.ply .gg)
Misc activity
ET TA_ABUSED_SERVICES Tunneling Service in DNS Lookup (* .ply .gg)
Potentially Bad Traffic
ET INFO playit .gg Tunneling Domain in DNS Lookup
No debug info