File name:

Spotify.exe

Full analysis: https://app.any.run/tasks/c303f255-cb31-4273-88b5-7760f94eb773
Verdict: Malicious activity
Threats:

Quasar is a very popular RAT in the world thanks to its code being available in open-source. This malware can be used to control the victim’s computer remotely.

Analysis date: September 28, 2024, 14:05:44
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
quasar
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

A724EBAD26B06027C490C4A109E683F6

SHA1:

E74395E68E7847A9DE28CC24292D8F437C47DD0A

SHA256:

A8B8CBBA2E3CE9FFC6A4797CAC24DFA728F2CE14877129E3DA2063F9150CC823

SSDEEP:

49152:x9gGOhX02hD2nPiLq3A6770DODdl/rADxXhCk/3DgP+xtsnvnU6cD85+hZRvjYzi:g2nP6q3A6770DODdl/rADxRLDg5wxbP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • Spotify.exe (PID: 4128)
      • Client.exe (PID: 4524)
    • QUASAR has been detected (YARA)

      • Client.exe (PID: 4524)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Spotify.exe (PID: 4128)
    • Starts itself from another location

      • Spotify.exe (PID: 4128)
    • Connects to unusual port

      • Client.exe (PID: 4524)
  • INFO

    • Checks supported languages

      • Spotify.exe (PID: 4128)
      • Client.exe (PID: 4524)
    • Reads Environment values

      • Spotify.exe (PID: 4128)
      • Client.exe (PID: 4524)
    • Reads the machine GUID from the registry

      • Spotify.exe (PID: 4128)
      • Client.exe (PID: 4524)
    • Reads the computer name

      • Spotify.exe (PID: 4128)
      • Client.exe (PID: 4524)
    • Creates files or folders in the user directory

      • Spotify.exe (PID: 4128)
    • The process uses the downloaded file

      • Spotify.exe (PID: 4128)
      • Client.exe (PID: 4524)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Quasar

(PID) Process(4524) Client.exe
Version1.4.1
C2 (2)147.185.221.21:4140
Sub_DirSubDir
Install_NameClient.exe
Mutexa81094a1-b4c3-4df3-95b8-9c14a17e5fe4
StartupSys
TagOffice04
LogDirLogs
SignatureambLZBuK5UL8EWf1rNVjkATTFRvr9piAIMyhmr9oJEcG8+c2GWhqyXs8S5J8WSTGTOamxSbwWlpEL1mWKOMciUOV/ewAphhAdc2tP1MolVivfoE4o4qfN5ZBxe0iGf6RnRIHmcPeHi263Lw9CS9EgxSYgw/eEs7L048mXbdvIU/oaYdyqVPXCwK/RrWXGNpdvL4LuJXlyhq9+spkaSdRrJO9lNEVIiph66Sgn9wjp1vsv/jaPecsXMNWjw7TiZP/5ONX20VS3xbxBO7tP+hPz4B8cIZia4pgy2vL/fzyEEVS...
CertificateMIIE9DCCAtygAwIBAgIQAKyCv06akVvL4NL8qd/vSTANBgkqhkiG9w0BAQ0FADAbMRkwFwYDVQQDDBBRdWFzYXIgU2VydmVyIENBMCAXDTI0MDkyNjA0NDYxOFoYDzk5OTkxMjMxMjM1OTU5WjAbMRkwFwYDVQQDDBBRdWFzYXIgU2VydmVyIENBMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAjG6Io8DF1aRB/NdzqHoAoe4K6LvyDAUZBcWBozSHpi9/P40/NIp9nkDHUf9MhhUetHCZsAm+...
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:03:12 16:16:39+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 3261952
InitializedDataSize: 71168
UninitializedDataSize: -
EntryPoint: 0x31e3fe
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.2.47.364
ProductVersionNumber: 1.2.47.364
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: Spotify
FileVersion: 1.2.47.364
InternalName: Spotify.exe
LegalCopyright: Copyright (c) 2024, Spotify Ltd
LegalTrademarks: -
OriginalFileName: Spotify.exe
ProductName: Spotify
ProductVersion: 1.2.47.364
AssemblyVersion: 1.2.47.364
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
116
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start spotify.exe #QUASAR client.exe

Process information

PID
CMD
Path
Indicators
Parent process
4128"C:\Users\admin\Desktop\Spotify.exe" C:\Users\admin\Desktop\Spotify.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Spotify
Exit code:
3
Version:
1.2.47.364
Modules
Images
c:\users\admin\desktop\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
4524"C:\Users\admin\AppData\Roaming\SubDir\Client.exe"C:\Users\admin\AppData\Roaming\SubDir\Client.exe
Spotify.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Spotify
Version:
1.2.47.364
Modules
Images
c:\users\admin\appdata\roaming\subdir\client.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Quasar
(PID) Process(4524) Client.exe
Version1.4.1
C2 (2)147.185.221.21:4140
Sub_DirSubDir
Install_NameClient.exe
Mutexa81094a1-b4c3-4df3-95b8-9c14a17e5fe4
StartupSys
TagOffice04
LogDirLogs
SignatureambLZBuK5UL8EWf1rNVjkATTFRvr9piAIMyhmr9oJEcG8+c2GWhqyXs8S5J8WSTGTOamxSbwWlpEL1mWKOMciUOV/ewAphhAdc2tP1MolVivfoE4o4qfN5ZBxe0iGf6RnRIHmcPeHi263Lw9CS9EgxSYgw/eEs7L048mXbdvIU/oaYdyqVPXCwK/RrWXGNpdvL4LuJXlyhq9+spkaSdRrJO9lNEVIiph66Sgn9wjp1vsv/jaPecsXMNWjw7TiZP/5ONX20VS3xbxBO7tP+hPz4B8cIZia4pgy2vL/fzyEEVS...
CertificateMIIE9DCCAtygAwIBAgIQAKyCv06akVvL4NL8qd/vSTANBgkqhkiG9w0BAQ0FADAbMRkwFwYDVQQDDBBRdWFzYXIgU2VydmVyIENBMCAXDTI0MDkyNjA0NDYxOFoYDzk5OTkxMjMxMjM1OTU5WjAbMRkwFwYDVQQDDBBRdWFzYXIgU2VydmVyIENBMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAjG6Io8DF1aRB/NdzqHoAoe4K6LvyDAUZBcWBozSHpi9/P40/NIp9nkDHUf9MhhUetHCZsAm+...
Total events
553
Read events
551
Write events
2
Delete events
0

Modification events

(PID) Process:(4128) Spotify.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Sys
Value:
"C:\Users\admin\AppData\Roaming\SubDir\Client.exe"
(PID) Process:(4524) Client.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Sys
Value:
"C:\Users\admin\AppData\Roaming\SubDir\Client.exe"
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
4128Spotify.exeC:\Users\admin\AppData\Roaming\SubDir\Client.exeexecutable
MD5:A724EBAD26B06027C490C4A109E683F6
SHA256:A8B8CBBA2E3CE9FFC6A4797CAC24DFA728F2CE14877129E3DA2063F9150CC823
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
30
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
8
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
8
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4524
Client.exe
147.185.221.21:4140
PLAYIT-GG
US
malicious
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.110
whitelisted

Threats

No threats detected
No debug info