File name:

Quasar.v1.4.0.zip

Full analysis: https://app.any.run/tasks/bc445b43-28ea-473e-96dc-4fb1b2c59737
Verdict: Malicious activity
Analysis date: June 19, 2021, 11:07:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

2F783DB7B6DB0B3E48AA984710FC3CE3

SHA1:

C6CF2B055C1BE0D5BA41F986BE49C82378AFB0E9

SHA256:

F2E8A0A730BE436EEA5CDCA3B229B945AD149A0E9E2CCA971CB998F88A08956D

SSDEEP:

49152:y88DVLeqK2sCAP4MujGKekr66JYIioycmkxRuru2PtjEPT8VimTl:y5NeqK2CPMj1z66hycLuK0wPIMq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Quasar.exe (PID: 3048)
      • Quasar.exe (PID: 2896)
      • SearchProtocolHost.exe (PID: 3396)
      • Quasar.exe (PID: 3168)
    • Application was dropped or rewritten from another process

      • Quasar.exe (PID: 3048)
      • Quasar.exe (PID: 2896)
      • Quasar.exe (PID: 3168)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3356)
    • Checks supported languages

      • WinRAR.exe (PID: 3356)
      • Quasar.exe (PID: 3048)
      • Quasar.exe (PID: 2896)
      • Quasar.exe (PID: 3168)
    • Reads the computer name

      • WinRAR.exe (PID: 3356)
      • Quasar.exe (PID: 3048)
      • Quasar.exe (PID: 2896)
      • Quasar.exe (PID: 3168)
    • Reads Environment values

      • Quasar.exe (PID: 3048)
      • Quasar.exe (PID: 2896)
      • Quasar.exe (PID: 3168)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 3356)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 3356)
  • INFO

    • Manual execution by user

      • Quasar.exe (PID: 3168)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Quasar v1.4.0/
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2020:06:05 17:56:18
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
5
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe quasar.exe no specs quasar.exe no specs searchprotocolhost.exe no specs quasar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2896"C:\Users\admin\AppData\Local\Temp\Rar$EXa3356.20595\Quasar v1.4.0\Quasar.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3356.20595\Quasar v1.4.0\Quasar.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Quasar Server
Exit code:
0
Version:
1.4.0
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\rar$exa3356.20595\quasar v1.4.0\quasar.exe
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3048"C:\Users\admin\AppData\Local\Temp\Rar$EXa3356.18659\Quasar v1.4.0\Quasar.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3356.18659\Quasar v1.4.0\Quasar.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Quasar Server
Exit code:
3489660927
Version:
1.4.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3356.18659\quasar v1.4.0\quasar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3168"C:\Users\admin\Desktop\Quasar.exe" C:\Users\admin\Desktop\Quasar.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Quasar Server
Exit code:
0
Version:
1.4.0
Modules
Images
c:\users\admin\desktop\quasar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3356"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Quasar.v1.4.0.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3396"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
2 111
Read events
2 079
Write events
32
Delete events
0

Modification events

(PID) Process:(3356) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3356) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3356) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3356) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3356) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Quasar.v1.4.0.zip
(PID) Process:(3356) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3356) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3356) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3356) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3356) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
36
Suspicious files
0
Text files
30
Unknown types
0

Dropped files

PID
Process
Filename
Type
3356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3356.18659\Quasar v1.4.0\3rdPartyLicenses\Open.Nat_license.txttext
MD5:E306664D753023CA56DBCA39110AE1C4
SHA256:D9E507EF9EDF463EAF893160F087A1C1A5325147DDD2C9A14C745454EB676DED
3356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3356.18659\Quasar v1.4.0\3rdPartyLicenses\Be.HexEditor_license.txttext
MD5:0A5C19336B04E958B8E528D66A61D048
SHA256:D691BA20526ED297DBABFD8BEEC2EF0DD2EE769783152BA5BCB9EB5037435EFB
3356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3356.18659\Quasar v1.4.0\3rdPartyLicenses\Mono.Cecil_license.txttext
MD5:4CC72AE97C8B623BD69A4DE2539F9728
SHA256:62DAD7936FC1214D0187B1DD27BD68EC055AF168B7FD1989CC8E36E0E2B9A990
3356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3356.18659\Quasar v1.4.0\3rdPartyLicenses\BouncyCastle_license.htmlhtml
MD5:BF8D5A737E70DD3493A475B8672F14DF
SHA256:6B73C0A42D138D1F05B527C7B936E79AF9F44A55D52E35F912DA15C0DEA43D30
3356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3356.18659\Quasar v1.4.0\3rdPartyLicenses\ResourceLib_license.txttext
MD5:26436010667B931EC76662B43577EAA2
SHA256:2D4F0B0A61082BEE4DED1E80664D228168AD379175AB930D7A00ECBCE163B2AE
3356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3356.18659\Quasar v1.4.0\3rdPartyLicenses\protobuf-net_license.txttext
MD5:DFE8687C4F152EE2B14F9BE8493FCA9C
SHA256:2B492575A689E98DA5CED83D486A95C03D99F4A318CD4E8B04FE9C8DD53D8E51
3356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3356.18659\Quasar v1.4.0\protobuf-net.dllexecutable
MD5:9FBB8CEC55B2115C00C0BA386C37CE62
SHA256:9F01D9F2ED07E630EC078EFA5D760762C3C8AD3B06E9E8A9062A37D63D57B026
3356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3356.18659\Quasar v1.4.0\Mono.Cecil.dllexecutable
MD5:7546ACEBC5A5213DEE2A5ED18D7EBC6C
SHA256:7744C9C84C28033BC3606F4DFCE2ADCD6F632E2BE7827893C3E2257100F1CF9E
3356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3356.18659\Quasar v1.4.0\Mono.Cecil.Pdb.dllexecutable
MD5:6CD3ED3DB95D4671B866411DB4950853
SHA256:D67EBD49241041E6B6191703A90D89E68D4465ADCE02C595218B867DF34581A3
3356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3356.18659\Quasar v1.4.0\Mono.Cecil.Rocks.dllexecutable
MD5:C8F36848CE8F13084B355C934FC91746
SHA256:A08C040912DF2A3C823ADE85D62239D56ABAA8F788A2684FB9D33961922687C7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info