File name:

1.4.1.0 Quasar Golden Edition.rar

Full analysis: https://app.any.run/tasks/99204864-8c1a-4149-b745-837d0f278ce8
Verdict: Malicious activity
Threats:

Quasar is a very popular RAT in the world thanks to its code being available in open-source. This malware can be used to control the victim’s computer remotely.

Analysis date: October 18, 2020, 17:40:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
rat
quasar
stealer
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

BB6863B30DE9EF74688682D18C1834DD

SHA1:

D7136008FA92E24B01F04EA9AD37F51023E14DDC

SHA256:

E1D773CFBA5B57CF411E4AE15B42A38CA33834A3E05F8CEC93918BFF81858085

SSDEEP:

98304:DWrf3vSrSSNc5nxdB4MrNxrTeKglFlhg50QhNiAE/UQ3aSfO5BnCSbUj8DKt4G:SrvqrSp7aGNxjglFDQ0IrKU+chq4G

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops/Copies Quasar RAT executable

      • WinRAR.exe (PID: 2688)
    • Loads dropped or rewritten executable

      • Quasar Golden Edition.exe (PID: 2136)
    • Application was dropped or rewritten from another process

      • Quasar Golden Edition.exe (PID: 3832)
      • Quasar Golden Edition.exe (PID: 2136)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2688)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 3952)
  • INFO

    • Manual execution by user

      • taskmgr.exe (PID: 1296)
      • cmd.exe (PID: 3952)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
70
Monitored processes
8
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe quasar golden edition.exe quasar golden edition.exe taskmgr.exe no specs cmd.exe taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1296"C:\Windows\system32\taskmgr.exe" /4C:\Windows\system32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2136"C:\Users\admin\AppData\Local\Temp\Rar$EXa2688.22395\1.4.1.0 Quasar Golden Edition\Quasar Golden Edition.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2688.22395\1.4.1.0 Quasar Golden Edition\Quasar Golden Edition.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Quasar Golden Edition
Exit code:
3762504530
Version:
1.4.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2688.22395\1.4.1.0 quasar golden edition\quasar golden edition.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2624TASKKILL /F svchost.exe /IMC:\Windows\system32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2668taskkillC:\Windows\system32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2688"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\1.4.1.0 Quasar Golden Edition.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3148TASKKILL /IM svchost.exe /FC:\Windows\system32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
3832"C:\Users\admin\AppData\Local\Temp\Rar$EXa2688.25451\1.4.1.0 Quasar Golden Edition\Quasar Golden Edition.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2688.25451\1.4.1.0 Quasar Golden Edition\Quasar Golden Edition.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Quasar Golden Edition
Exit code:
3762504530
Version:
1.4.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2688.25451\1.4.1.0 quasar golden edition\quasar golden edition.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3952"C:\Windows\System32\cmd.exe" C:\Windows\System32\cmd.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
3221225786
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
649
Read events
624
Write events
25
Delete events
0

Modification events

(PID) Process:(2688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2688) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\1.4.1.0 Quasar Golden Edition.rar
(PID) Process:(2688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
28
Suspicious files
0
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
2688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2688.22395\1.4.1.0 Quasar Golden Edition\client.binexecutable
MD5:19A3AB679DF06AAFF3D972CD014CA769
SHA256:3AE294870C3F566D1FA8D05C04930B6A60569D23C4341DD1033F41530A3E8E6D
2688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2688.22395\1.4.1.0 Quasar Golden Edition\Include\dotNET_Reactor.exe.configtext
MD5:350126131A856BDD61F79E7D3517C1EF
SHA256:3558DB8E365AD533C73D777F00A25F9DD493A4B19A9457904054BD5F07A6E0B9
2688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2688.22395\1.4.1.0 Quasar Golden Edition\Include\dotNET_Reactor.exeexecutable
MD5:7429E30CAA2A8B41D926FFEF1A05B347
SHA256:1EFC5368BCD9704D7DF85E2E143936D6EE4509AC31A7CA6D3EB4CF3B18C5EF27
2688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2688.22395\1.4.1.0 Quasar Golden Edition\Include\icon.icoimage
MD5:BF70767BFDE43D3EC0C098E6BDEB16BB
SHA256:2C1014FEF843A5C2953F6C10A5FA4CF518CAA716D46098FA468AF2537E64C93F
2688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2688.22395\1.4.1.0 Quasar Golden Edition\Include\mpress.exeexecutable
MD5:8B632BFC3FE653A510CBA277C2D699D1
SHA256:2852680C94A9D68CDAB285012D9328A1CECA290DB60C9E35155C2BB3E46A41B4
2688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2688.22395\1.4.1.0 Quasar Golden Edition\Include\NCCheck.dllexecutable
MD5:569052631A6B80C1C6A336C10C978B02
SHA256:C41CD461470FF3C936E225CEA37E5190CB06E3CD70A3D76CA8E5D3ACEEAD5493
2688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2688.22395\1.4.1.0 Quasar Golden Edition\Include\reactor.nrcfgtext
MD5:F6F470AB378C9AF0CD72EE4D8F36F7A3
SHA256:AC3608A4BA2947EF197BC12F6A6DDA90E2351A6918524B0CF7B4926D47DCB36C
2688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2688.22395\1.4.1.0 Quasar Golden Edition\Include\VS08ReactorAddin.dllexecutable
MD5:B4C1E8023BE1BD3AF8425885ED5D02CE
SHA256:1952313F3A5C3B4E7A1269238DC070301C356BFB876471332D6439B6D3EEFD12
2688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2688.22395\1.4.1.0 Quasar Golden Edition\Include\nrcfg.icoimage
MD5:FF77CAF6F78CA711630202FEBBF19BA7
SHA256:7A8F9EB4CF92CB24B092FC852B602AB06601137836D6594DA822783890C520B8
2688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2688.22395\1.4.1.0 Quasar Golden Edition\Include\NCC2.dllexecutable
MD5:12E7983A050A5F7F7B501D3CDA914248
SHA256:A0B6BB521E52A99ABF5AC1017302DA014D37296619078D42D9EDF5D86D137F63
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info