Quasar is a very popular RAT in the world thanks to its code being available in the open-source. This malware can be used to remotely control the victim’s computer.
MALICIOUS | SUSPICIOUS | INFO |
---|---|---|
Application was dropped or rewritten from another process
|
Creates files in the user directory
|
No info indicators. |
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0000111F | 0x00001200 | IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ | 6.0953 |
.rdata | 0x00003000 | 0x00000C08 | 0x00000E00 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ | 4.30092 |
.data | 0x00004000 | 0x00055174 | 0x00055000 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE | 7.76242 |
.rsrc | 0x0005A000 | 0x00013D70 | 0x00013E00 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ | 7.54423 |
.reloc | 0x0006E000 | 0x00000174 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ | 5.15314 |
No exports.
Click at the process to see the details.
Image |
---|
c:\users\admin\appdata\local\temp\rc_cleaner.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\vcruntime140.dll |
c:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll |
c:\windows\system32\ucrtbase.dll |
c:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll |
c:\windows\system32\api-ms-win-core-file-l2-1-0.dll |
c:\windows\system32\api-ms-win-core-localization-l1-2-0.dll |
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll |
c:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll |
c:\windows\system32\api-ms-win-core-file-l1-2-0.dll |
c:\windows\system32\api-ms-win-crt-string-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-math-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll |
c:\windows\system32\apphelp.dll |
Image |
---|
c:\windows\system32\cmd.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\winbrand.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\apphelp.dll |
c:\users\admin\appdata\roamingwin643.exe |
Image |
---|
c:\users\admin\appdata\roamingwin643.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\mscoree.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\version.dll |
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll |
c:\windows\system32\msvcr120_clr0400.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system\52cca48930e580e3189eac47158c20be\system.ni.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\646b4b01cb29986f8e076aa65c9e9753\system.drawing.ni.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\5aac750b35b27770dccb1a43f83cced7\system.windows.forms.ni.dll |
c:\windows\system32\uxtheme.dll |
c:\windows\microsoft.net\assembly\gac_msil\system.windows.forms\v4.0_4.0.0.0__b77a5c561934e089\system.windows.forms.dll |
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\rsaenh.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\55560c2014611e9119f99923c9ebdeef\system.core.ni.dll |
c:\windows\system32\bcrypt.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.management\4dfa27fdd6a4cce26f99585e1c744f9b\system.management.ni.dll |
c:\windows\system32\rpcrtremote.dll |
c:\windows\system32\clbcatq.dll |
c:\windows\system32\wbem\wmiutils.dll |
c:\windows\system32\wbemcomn.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\wbem\wbemprox.dll |
c:\windows\microsoft.net\framework\v4.0.30319\wminet_utils.dll |
c:\windows\system32\wbem\wbemsvc.dll |
c:\windows\system32\wbem\fastprox.dll |
c:\windows\system32\ntdsapi.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.runteb92aa12#\c56771a9cfb87e660d60453e232abe27\system.runtime.serialization.ni.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\smdiagnostics\4a2a848ea1fea1a74d5aa2f1c21c5ce8\smdiagnostics.ni.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\46957030830964165644b52b0696c5d9\system.configuration.ni.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\d86b080a37c60a872c82b912a2a63dac\system.xml.ni.dll |
c:\windows\system32\rasapi32.dll |
c:\windows\system32\rasman.dll |
c:\windows\system32\rtutils.dll |
c:\windows\system32\mswsock.dll |
c:\windows\system32\wshtcpip.dll |
c:\windows\system32\wship6.dll |
c:\windows\system32\winhttp.dll |
c:\windows\system32\webio.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\credssp.dll |
c:\windows\system32\iphlpapi.dll |
c:\windows\system32\winnsi.dll |
c:\windows\system32\dhcpcsvc6.dll |
c:\windows\system32\dhcpcsvc.dll |
c:\windows\system32\dnsapi.dll |
c:\windows\system32\rasadhlp.dll |
c:\windows\system32\fwpuclnt.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.servd1dec626#\52e9ac689c75dd011f0f7e827551e985\system.servicemodel.internals.ni.dll |
c:\windows\system32\apphelp.dll |
c:\users\admin\appdata\roaming\systemr\systemr.exe |
Image |
---|
c:\users\admin\appdata\roaming\systemr\systemr.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\mscoree.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\version.dll |
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll |
c:\windows\system32\msvcr120_clr0400.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system\52cca48930e580e3189eac47158c20be\system.ni.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\646b4b01cb29986f8e076aa65c9e9753\system.drawing.ni.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\5aac750b35b27770dccb1a43f83cced7\system.windows.forms.ni.dll |
c:\windows\system32\uxtheme.dll |
c:\windows\microsoft.net\assembly\gac_msil\system.windows.forms\v4.0_4.0.0.0__b77a5c561934e089\system.windows.forms.dll |
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\rsaenh.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\55560c2014611e9119f99923c9ebdeef\system.core.ni.dll |
c:\windows\system32\bcrypt.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.management\4dfa27fdd6a4cce26f99585e1c744f9b\system.management.ni.dll |
c:\windows\system32\clbcatq.dll |
c:\windows\system32\wbem\wmiutils.dll |
c:\windows\system32\wbemcomn.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\rpcrtremote.dll |
c:\windows\system32\wbem\wbemprox.dll |
c:\windows\microsoft.net\framework\v4.0.30319\wminet_utils.dll |
c:\windows\system32\wbem\wbemsvc.dll |
c:\windows\system32\wbem\fastprox.dll |
c:\windows\system32\ntdsapi.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.runteb92aa12#\c56771a9cfb87e660d60453e232abe27\system.runtime.serialization.ni.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\smdiagnostics\4a2a848ea1fea1a74d5aa2f1c21c5ce8\smdiagnostics.ni.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\46957030830964165644b52b0696c5d9\system.configuration.ni.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\d86b080a37c60a872c82b912a2a63dac\system.xml.ni.dll |
c:\windows\system32\rasapi32.dll |
c:\windows\system32\rasman.dll |
c:\windows\system32\rtutils.dll |
c:\windows\system32\mswsock.dll |
c:\windows\system32\wshtcpip.dll |
c:\windows\system32\wship6.dll |
c:\windows\system32\winhttp.dll |
c:\windows\system32\webio.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\credssp.dll |
c:\windows\system32\iphlpapi.dll |
c:\windows\system32\winnsi.dll |
c:\windows\system32\dhcpcsvc6.dll |
c:\windows\system32\dhcpcsvc.dll |
c:\windows\system32\dnsapi.dll |
c:\windows\system32\rasadhlp.dll |
c:\windows\system32\fwpuclnt.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.servd1dec626#\52e9ac689c75dd011f0f7e827551e985\system.servicemodel.internals.ni.dll |
c:\windows\system32\psapi.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2652 | RoamingWin643.exe | GET | 200 | 185.194.141.58:80 | http://ip-api.com/json/ | DE |
text
|
|
shared |
2136 | SystemR.exe | GET | 200 | 185.194.141.58:80 | http://ip-api.com/json/ | DE |
text
|
|
shared |
PID | Process | IP | ASN | CN | Reputation |
---|---|---|---|---|---|
2652 | RoamingWin643.exe | 185.194.141.58:80 | netcup GmbH | DE | malicious |
2136 | SystemR.exe | 185.194.141.58:80 | netcup GmbH | DE | malicious |
2136 | SystemR.exe | 2.47.209.176:1604 | Vodafone Italia S.p.A. | IT | unknown |
Domain | IP | Reputation |
---|---|---|
ip-api.com | 185.194.141.58
|
shared |
gingles.dynu.net | 2.47.209.176
|
malicious |
PID | Process | Class | Message |
---|---|---|---|
2652 | RoamingWin643.exe | Potential Corporate Privacy Violation | ET POLICY External IP Lookup ip-api.com |
2652 | RoamingWin643.exe | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
2652 | RoamingWin643.exe | A Network Trojan was detected | MALWARE [PTsecurity] Quasar 1.3 RAT IP Lookup ip-api.com (HTTP headeer) |
2136 | SystemR.exe | Potential Corporate Privacy Violation | ET POLICY External IP Lookup ip-api.com |
2136 | SystemR.exe | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
2136 | SystemR.exe | A Network Trojan was detected | MALWARE [PTsecurity] Quasar 1.3 RAT IP Lookup ip-api.com (HTTP headeer) |
No debug info.