| File name: | Bazaar.2020.02.7z |
| Full analysis: | https://app.any.run/tasks/4ac4d62d-bc1e-4b2f-8961-c9372f75c92a |
| Verdict: | Malicious activity |
| Threats: | Quasar is a very popular RAT in the world thanks to its code being available in open-source. This malware can be used to control the victim’s computer remotely. |
| Analysis date: | December 03, 2023, 20:43:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | A2FC1E0D85DA197A26203E22BDD1B5A2 |
| SHA1: | 4C2F2158F440347A0F722CD81EB806E28481B868 |
| SHA256: | 7559E6CA8B77400F88BF4E67208A1C32570A670068ECCAE9E3D226CC5471BD47 |
| SSDEEP: | 98304:kZmkhJvBGT1MBhAIF4p4JRERrUgzyGo+fBuAA5X9X6K+8PyhlBe8S73vf6MNcD8r:aU3m1fqRVJZ7QOuK+v |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 528 | "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "C:\Users\admin\Desktop\bazaar.2020.02\Backdoor.Win32.Delf.aecw-a2f4d3da25e52d88eafb7a7da242e9bb507fe4626af58ca3b8c1a13e391c2000" | C:\Program Files\Mozilla Firefox\firefox.exe | — | rundll32.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 880 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2296 --field-trial-handle=1212,i,10716249340697070423,7028022415260173080,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1032 | "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url C:\Users\admin\Desktop\bazaar.2020.02\Backdoor.Win32.Delf.aecw-a2f4d3da25e52d88eafb7a7da242e9bb507fe4626af58ca3b8c1a13e391c2000 | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1668 | "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "C:\Users\admin\Downloads\Backdoor.Win32.Delf.aecw-a2f4d3da25e52d88eafb7a7da242e9bb507fe4626af58ca3b8c1a13e391c2000" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1760 | "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url C:\Users\admin\Downloads\Backdoor.Win32.Delf.aecw-a2f4d3da25e52d88eafb7a7da242e9bb507fe4626af58ca3b8c1a13e391c2000 | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1884 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1032.3.692967021\739957530" -childID 2 -isForBrowser -prefsHandle 2816 -prefMapHandle 2812 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 948 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7ca898e3-1316-41f8-8ddf-d7fd7f3e3296} 1032 "\\.\pipe\gecko-crash-server-pipe.1032" 2828 16176b20 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1888 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=4480 --field-trial-handle=1212,i,10716249340697070423,7028022415260173080,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2096 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1032.2.1233187255\405887856" -childID 1 -isForBrowser -prefsHandle 2064 -prefMapHandle 2060 -prefsLen 29630 -prefMapSize 244195 -jsInitHandle 948 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {ecdba44a-2d05-40b0-9269-c85aa70bbaf2} 1032 "\\.\pipe\gecko-crash-server-pipe.1032" 2076 12720560 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2108 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\bazaar.2020.02\HEUR-Backdoor.MSIL.Crysan.gen-4ece7a3cd6313c022ce3d30028a8af4f4f4da6a35efcddb8136b4bb5520fdb21 | C:\Windows\System32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2108 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1032.4.1875986003\2037159752" -childID 3 -isForBrowser -prefsHandle 3668 -prefMapHandle 3640 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 948 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {94c6facc-4eca-4b0a-8dd8-b97a6eec2ffe} 1032 "\\.\pipe\gecko-crash-server-pipe.1032" 3700 1504cc90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (3060) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2528) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2528) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3060 | WinRAR.exe | C:\Users\admin\Desktop\bazaar.2020.02\Backdoor.Win32.DarkKomet.aagt-4c1b6befb06152412567869f27c006cba39f4ac3b1c5dbcf8694a65367444df5 | executable | |
MD5:B7B88850BC66C349BC02F81A3B443F39 | SHA256:4C1B6BEFB06152412567869F27C006CBA39F4AC3B1C5DBCF8694A65367444DF5 | |||
| 3060 | WinRAR.exe | C:\Users\admin\Desktop\bazaar.2020.02\Backdoor.MSIL.Agent.jdt-aa918b196328f1fe341b5b48cb5d28f31a94b92b279fcf36baaea55a0a8886f1 | executable | |
MD5:A5C91C0DF00109626C011EB185E94138 | SHA256:AA918B196328F1FE341B5B48CB5D28F31A94B92B279FCF36BAAEA55A0A8886F1 | |||
| 3060 | WinRAR.exe | C:\Users\admin\Desktop\bazaar.2020.02\Backdoor.MSIL.Agent.jdt-72fd107044ae159a7a80813fe902a132f12eedd01c63fd9e506cf05e088e7491 | executable | |
MD5:F54EEA2B9A7C0259B87A5303A526D818 | SHA256:72FD107044AE159A7A80813FE902A132F12EEDD01C63FD9E506CF05E088E7491 | |||
| 3060 | WinRAR.exe | C:\Users\admin\Desktop\bazaar.2020.02\HEUR-Backdoor.MSIL.Crysan.gen-2b70dd97d36efbbadd5f63afc22e28dc53d26302bae846b4f4e49e27cf95a70f | executable | |
MD5:8944E61729E65362B848DCC0268E9DDF | SHA256:2B70DD97D36EFBBADD5F63AFC22E28DC53D26302BAE846B4F4E49E27CF95A70F | |||
| 3060 | WinRAR.exe | C:\Users\admin\Desktop\bazaar.2020.02\Backdoor.Win32.Delf.aecw-fa3981228b5b124a8b51fa64f8b6d5d05899165647dc50322b717d7ab63d4997 | executable | |
MD5:7705CBB21D01877E944FDA88286AC48A | SHA256:FA3981228B5B124A8B51FA64F8B6D5D05899165647DC50322B717D7AB63D4997 | |||
| 3060 | WinRAR.exe | C:\Users\admin\Desktop\bazaar.2020.02\Backdoor.Win32.Delf.aecw-a2f4d3da25e52d88eafb7a7da242e9bb507fe4626af58ca3b8c1a13e391c2000 | executable | |
MD5:94D715C76354182482DCC8FB446A1BE7 | SHA256:A2F4D3DA25E52D88EAFB7A7DA242E9BB507FE4626AF58CA3B8C1A13E391C2000 | |||
| 3060 | WinRAR.exe | C:\Users\admin\Desktop\bazaar.2020.02\HEUR-Backdoor.MSIL.Crysan.gen-0a276fdaf3367ca3fd4cf90eb338dd3d0575ba3979f1bd609ce58e13e2aa0a8e | executable | |
MD5:B36ED4B297C327EB67746E85FE4434F4 | SHA256:0A276FDAF3367CA3FD4CF90EB338DD3D0575BA3979F1BD609CE58E13E2AA0A8E | |||
| 3060 | WinRAR.exe | C:\Users\admin\Desktop\bazaar.2020.02\Backdoor.Win32.Parazit.aw-4f54c2e0def0a2a5b478220b3ddbccc3ee2a7302cddbfe0e8e1d394587589d88 | executable | |
MD5:D52448CB39E67D27DAE28F60906AFFCC | SHA256:4F54C2E0DEF0A2A5B478220B3DDBCCC3EE2A7302CDDBFE0E8E1D394587589D88 | |||
| 3060 | WinRAR.exe | C:\Users\admin\Desktop\bazaar.2020.02\HEUR-Backdoor.MSIL.Crysan.gen-0eeb561ea16bf80e301847add0363445976f5ab518d23e499cbf1f7ce9e6fc59 | executable | |
MD5:34DD1859E3B572CB15C85C7255D1A2DD | SHA256:0EEB561EA16BF80E301847ADD0363445976F5AB518D23E499CBF1F7CE9E6FC59 | |||
| 3060 | WinRAR.exe | C:\Users\admin\Desktop\bazaar.2020.02\HEUR-Backdoor.MSIL.Agent.gen-0eb3ab9e4c6bc5903674d8f9b36a1a59825fa4e1c2d7209be4d7a0c16dc6168f | executable | |
MD5:F2E6FEBD5AC77954B3C8F460D5FA2598 | SHA256:0EB3AB9E4C6BC5903674D8F9B36A1A59825FA4E1C2D7209BE4D7A0C16DC6168F | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3140 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2528 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3140 | msedge.exe | 23.211.9.234:80 | go.microsoft.com | AKAMAI-AS | DE | unknown |
3140 | msedge.exe | 20.31.251.109:443 | nav-edge.smartscreen.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
3140 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
3140 | msedge.exe | 23.211.9.234:443 | go.microsoft.com | AKAMAI-AS | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
config.edge.skype.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
nav-edge.smartscreen.microsoft.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
edge-http.microsoft.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| shared |
Process | Message |
|---|---|
msedge.exe | [1203/204358.558:ERROR:exception_handler_server.cc(527)] ConnectNamedPipe: The pipe is being closed. (0xE8)
|
msedge.exe | [1203/204404.974:ERROR:exception_handler_server.cc(527)] ConnectNamedPipe: The pipe is being closed. (0xE8)
|