File name:

Heart-Sender-V1.2_Cracked_by_JC0der-FireEye.rar

Full analysis: https://app.any.run/tasks/31880028-2d60-4347-944a-a0ec8ac527f4
Verdict: Malicious activity
Threats:

Quasar is a very popular RAT in the world thanks to its code being available in open-source. This malware can be used to control the victim’s computer remotely.

Analysis date: August 05, 2020, 20:47:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
rat
quasar
evasion
trojan
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

0737CCF9E78859896254F0D119AA1AF9

SHA1:

F4DE3D02DF395F9C1AEC3ED0F39496EF0A75707B

SHA256:

705C30ECABF1F694C24F521D35CBF3027798DD6F6965134C98F9CAD0CF8833CE

SSDEEP:

12288:15AFdXQ59vpVC1lorbwS/hPW8veGzKopC:IA51zC1iwwPW8HKj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Heart-Sender-V1.2 Cracked by JC0der-FireEye.exe (PID: 3992)
      • Loader1.exe (PID: 2344)
      • Heart.exe (PID: 3776)
      • config.exe (PID: 2432)
      • Loader3.exe (PID: 3216)
      • Loader4.exe (PID: 2220)
      • Loader2.exe (PID: 2956)
      • config.exe (PID: 2552)
      • svchost.exe (PID: 676)
      • svchost.exe (PID: 3012)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3480)
    • Executes PowerShell scripts

      • cmd.exe (PID: 1728)
      • cmd.exe (PID: 2700)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 952)
      • schtasks.exe (PID: 2264)
    • Drops/Copies Quasar RAT executable

      • Loader3.exe (PID: 3216)
    • Uses Task Scheduler to run other applications

      • cmd.exe (PID: 1728)
    • QUASAR was detected

      • svchost.exe (PID: 3012)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2684)
      • Loader1.exe (PID: 2344)
      • Loader3.exe (PID: 3216)
      • Loader4.exe (PID: 2220)
      • Loader2.exe (PID: 2956)
    • Starts CMD.EXE for commands execution

      • Heart-Sender-V1.2 Cracked by JC0der-FireEye.exe (PID: 3992)
      • config.exe (PID: 2432)
      • config.exe (PID: 2552)
    • Creates files in the user directory

      • powershell.exe (PID: 2360)
      • powershell.exe (PID: 1216)
      • powershell.exe (PID: 2396)
      • powershell.exe (PID: 1924)
      • powershell.exe (PID: 2388)
      • powershell.exe (PID: 1396)
      • powershell.exe (PID: 2120)
      • powershell.exe (PID: 1956)
      • Loader3.exe (PID: 3216)
      • Loader4.exe (PID: 2220)
      • powershell.exe (PID: 2096)
      • powershell.exe (PID: 1556)
      • svchost.exe (PID: 3012)
    • Uses ATTRIB.EXE to modify file attributes

      • cmd.exe (PID: 1728)
    • Creates executable files which already exist in Windows

      • Loader3.exe (PID: 3216)
      • Loader4.exe (PID: 2220)
    • Executed via Task Scheduler

      • svchost.exe (PID: 676)
      • svchost.exe (PID: 3012)
    • Checks for external IP

      • svchost.exe (PID: 3012)
  • INFO

    • Manual execution by user

      • Heart-Sender-V1.2 Cracked by JC0der-FireEye.exe (PID: 3992)
    • Dropped object may contain Bitcoin addresses

      • Loader1.exe (PID: 2344)
      • Loader4.exe (PID: 2220)
      • Loader2.exe (PID: 2956)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
71
Monitored processes
29
Malicious processes
12
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs heart-sender-v1.2 cracked by jc0der-fireeye.exe cmd.exe no specs loader1.exe heart.exe no specs config.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs powershell.exe no specs powershell.exe no specs powershell.exe no specs powershell.exe no specs powershell.exe no specs powershell.exe no specs schtasks.exe no specs schtasks.exe no specs attrib.exe no specs attrib.exe no specs loader3.exe loader4.exe loader2.exe config.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs svchost.exe no specs #QUASAR svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
676C:\Users\admin\AppData\Roaming\Microsoft\svchost10\svchost.exe C:\Users\admin\AppData\Roaming\Microsoft\svchost10\svchost.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Host Process for Windows Services
Exit code:
0
Version:
7.2.5.0 (WinBuild. 7.2.5.0)
Modules
Images
c:\users\admin\appdata\roaming\microsoft\svchost10\svchost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
952schtasks /create /sc minute /mo 1 /tn "Microsoft\svchost\svchost9" /tr "C:\Users\admin\AppData\Roaming\Microsoft\svchost9\svchost.exe" /RL HIGHEST /fC:\Windows\system32\schtasks.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1216powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "C:\users" -ForceC:\Windows\System32\WindowsPowerShell\v1.0\powershell.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
1396powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "$env:APPDATA\Microsoft\svchost10" -ForceC:\Windows\System32\WindowsPowerShell\v1.0\powershell.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
1556powershell Remove-MpPreference -ExclusionPath "C:\users" -ForceC:\Windows\System32\WindowsPowerShell\v1.0\powershell.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
1728"C:\Windows\system32\cmd.exe" /c "C:\Users\admin\AppData\Local\Temp\270C.tmp\270D.tmp\270E.bat C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\config.exe"C:\Windows\system32\cmd.execonfig.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1924powershell Add-MpPreference -ExclusionPath "$env:TEMP" -forceC:\Windows\System32\WindowsPowerShell\v1.0\powershell.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
1956powershell Add-MpPreference -ExclusionPath "$env:APPDATA\Microsoft\svchost10" -forceC:\Windows\System32\WindowsPowerShell\v1.0\powershell.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
2096powershell -inputformat none -outputformat none -NonInteractive -Command Remove-MpPreference -ExclusionPath "C:\users" -ForceC:\Windows\System32\WindowsPowerShell\v1.0\powershell.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
2120powershell Add-MpPreference -ExclusionPath "$env:APPDATA\Microsoft\svchost9" -forceC:\Windows\System32\WindowsPowerShell\v1.0\powershell.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
Total events
4 280
Read events
3 674
Write events
606
Delete events
0

Modification events

(PID) Process:(2684) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2684) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2684) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2684) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Heart-Sender-V1.2_Cracked_by_JC0der-FireEye.rar
(PID) Process:(2684) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2684) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2684) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2684) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2684) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
(PID) Process:(2684) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
Executable files
12
Suspicious files
21
Text files
12
Unknown types
0

Dropped files

PID
Process
Filename
Type
1216powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\JH8DHWAY2U7XCL1TAVSR.temp
MD5:
SHA256:
2360powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\X1PIORTNJZZDHRVQGJM4.temp
MD5:
SHA256:
2396powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\T9FAZZTOZ069WF2THOTT.temp
MD5:
SHA256:
2684WinRAR.exeC:\Users\admin\Desktop\Heart-Sender-V1.2 Cracked by JC0der-FireEye.exeexecutable
MD5:E2346FDA4AA8A57821D99F023FF5FB83
SHA256:0C802F556E4C59A0499D56D6A75EED31580582DF5868C54A4DECD6B13A94236C
2120powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\OW2WB1HD8HF78Z4DYEE2.temp
MD5:
SHA256:
2684WinRAR.exeC:\Users\admin\Desktop\Config\Config\Heart.exeexecutable
MD5:5E718B467DF9A3E96680CC6AB75D5115
SHA256:1045A29A6D8D69A88BEEAEB9217E247FCD14F21394EF9D7C002396CB2177B991
2684WinRAR.exeC:\Users\admin\Desktop\Config\Loader1.exeexecutable
MD5:1783B29684F9248CF30A7ACBC23E549A
SHA256:7EEE4DEB0EC25F61680C36B3410E461A303CF4988D172142B7D4B38008D804AB
1396powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\EOC7IG8Q205R7FF1SVJA.temp
MD5:
SHA256:
2684WinRAR.exeC:\Users\admin\Desktop\Config\Loader3.exeexecutable
MD5:B3DCAF03FA0A1A4E516578932BB70B3E
SHA256:3145C1044AC56B0E057FC836D3CF159B0351E0FDA464A96AEFA0A55535F1E00B
2684WinRAR.exeC:\Users\admin\Desktop\Config\Loader4.exeexecutable
MD5:B5F54C36C11819305300EF10B1FCD1CB
SHA256:9BC90D8AF8F5F033683B1EE5E8597702FC1AD808936168BEDDD88F16232B88B0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
24
DNS requests
1
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3012
svchost.exe
GET
200
208.95.112.1:80
http://ip-api.com/json/
unknown
text
319 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3012
svchost.exe
208.95.112.1:80
ip-api.com
IBURST
malicious
3012
svchost.exe
185.81.157.212:60010
Inulogic Sarl
FR
suspicious
185.81.157.212:60010
Inulogic Sarl
FR
suspicious

DNS requests

Domain
IP
Reputation
ip-api.com
  • 208.95.112.1
malicious

Threats

PID
Process
Class
Message
3012
svchost.exe
Potential Corporate Privacy Violation
ET POLICY External IP Lookup ip-api.com
3012
svchost.exe
Potential Corporate Privacy Violation
AV POLICY Internal Host Retrieving External IP Address (ip-api. com)
3012
svchost.exe
A Network Trojan was detected
REMOTE [PTsecurity] Quasar.RAT IP Lookup
1 ETPRO signatures available at the full report
No debug info