File name:

Adobe Download Manager.exe

Full analysis: https://app.any.run/tasks/237645f4-16ce-489e-810c-224fded6cf30
Verdict: Malicious activity
Threats:

Quasar is a very popular RAT in the world thanks to its code being available in open-source. This malware can be used to control the victim’s computer remotely.

Analysis date: December 21, 2023, 18:19:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
rat
quasar
evasion
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

2E9BA9334449304220A549E7A75447F4

SHA1:

791D1648EE703E05B4749FCB99C8F45692E73787

SHA256:

F859BDDDA5D049E5449032B8A4373515A6A06CBC2019F9FC1C0C269BA4D90153

SSDEEP:

98304:GAGQX21RBt7QjTmcaTH/vU4do9Pcjq1GvXB1sg58N32+Rr181vWDZT3FcIwEAiRf:zr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Uses Task Scheduler to run other applications

      • Adobe Download Manager.exe (PID: 2040)
      • SystemPropertiesPerformance.exe (PID: 1528)
    • Changes the autorun value in the registry

      • winsock.exe (PID: 1832)
    • QUASAR has been detected (YARA)

      • winsock.exe (PID: 1832)
      • Adobe Download Manager.exe (PID: 2040)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Adobe Download Manager.exe (PID: 296)
      • windef.exe (PID: 1056)
      • winsock.exe (PID: 1832)
      • Adobe Download Manager.exe (PID: 2040)
      • SystemPropertiesPerformance.exe (PID: 1036)
      • SystemPropertiesPerformance.exe (PID: 1528)
    • Checks for external IP

      • windef.exe (PID: 1056)
      • winsock.exe (PID: 1832)
    • Starts application with an unusual extension

      • cmd.exe (PID: 2296)
    • Runs PING.EXE to delay simulation

      • cmd.exe (PID: 2296)
    • Executing commands from a ".bat" file

      • winsock.exe (PID: 1832)
    • Starts CMD.EXE for commands execution

      • winsock.exe (PID: 1832)
  • INFO

    • Checks supported languages

      • Adobe Download Manager.exe (PID: 2040)
      • vnc.exe (PID: 1432)
      • winsock.exe (PID: 1832)
      • chcp.com (PID: 2096)
      • windef.exe (PID: 1056)
      • winsock.exe (PID: 2736)
      • SystemPropertiesPerformance.exe (PID: 1528)
      • SystemPropertiesPerformance.exe (PID: 1036)
      • vnc.exe (PID: 2580)
      • Adobe Download Manager.exe (PID: 296)
      • windef.exe (PID: 2760)
    • Drops the executable file immediately after the start

      • Adobe Download Manager.exe (PID: 2040)
      • windef.exe (PID: 1056)
    • Reads the machine GUID from the registry

      • Adobe Download Manager.exe (PID: 2040)
      • windef.exe (PID: 1056)
      • Adobe Download Manager.exe (PID: 296)
      • winsock.exe (PID: 1832)
      • winsock.exe (PID: 2736)
      • SystemPropertiesPerformance.exe (PID: 1528)
      • windef.exe (PID: 2760)
      • SystemPropertiesPerformance.exe (PID: 1036)
    • Create files in a temporary directory

      • Adobe Download Manager.exe (PID: 2040)
      • winsock.exe (PID: 1832)
      • SystemPropertiesPerformance.exe (PID: 1528)
    • Reads the computer name

      • Adobe Download Manager.exe (PID: 296)
      • Adobe Download Manager.exe (PID: 2040)
      • windef.exe (PID: 1056)
      • winsock.exe (PID: 1832)
      • winsock.exe (PID: 2736)
      • SystemPropertiesPerformance.exe (PID: 1528)
      • windef.exe (PID: 2760)
      • SystemPropertiesPerformance.exe (PID: 1036)
    • Drops/Copies Quasar RAT executable

      • Adobe Download Manager.exe (PID: 2040)
      • windef.exe (PID: 1056)
    • Checks proxy server information

      • Adobe Download Manager.exe (PID: 296)
      • SystemPropertiesPerformance.exe (PID: 1036)
    • Starts itself from another location

      • windef.exe (PID: 1056)
    • Reads Environment values

      • windef.exe (PID: 1056)
      • winsock.exe (PID: 1832)
      • SystemPropertiesPerformance.exe (PID: 1036)
      • Adobe Download Manager.exe (PID: 296)
    • Creates files or folders in the user directory

      • windef.exe (PID: 1056)
      • winsock.exe (PID: 1832)
    • Reads mouse settings

      • Adobe Download Manager.exe (PID: 2040)
      • SystemPropertiesPerformance.exe (PID: 1528)
    • Reads product name

      • Adobe Download Manager.exe (PID: 296)
      • SystemPropertiesPerformance.exe (PID: 1036)
    • The executable file from the user directory is run by the CMD process

      • winsock.exe (PID: 2736)
    • Application launched itself

      • Adobe Download Manager.exe (PID: 2040)
      • SystemPropertiesPerformance.exe (PID: 1528)
    • The process executes via Task Scheduler

      • SystemPropertiesPerformance.exe (PID: 1528)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Quasar

(PID) Process(1832) winsock.exe
Version1.3.0.0
C2 (3)5.8.88.191:443
sockartek.icu:443
Sub_DirSubDir
Install_Namewinsock.exe
MutexQSR_MUTEX_0kBRNrRz5TDLEQouI0
Startupwin defender run
TagEbayProfiles
LogDirLogs
Signature
Certificate
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (17.3)
.dll | Win32 Dynamic Link Library (generic) (4.1)
.exe | Win32 Executable (generic) (2.8)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:03:12 14:38:44+01:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 581120
InitializedDataSize: 1527296
UninitializedDataSize: -
EntryPoint: 0x27dcd
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: Adobe Download Manager
OriginalFileName: Adobe Download Manager
CompanyName: Adobe Systems Incorporated
FileVersion: ...
LegalCopyright: Copyright 2018 Adobe Incorporated. All rights reserved.
ProductName: Adobe Download Manager
ProductVersion: ...
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
58
Monitored processes
17
Malicious processes
3
Suspicious processes
3

Behavior graph

Click at the process to see the details
start #QUASAR adobe download manager.exe no specs vnc.exe no specs svchost.exe windef.exe adobe download manager.exe no specs schtasks.exe no specs #QUASAR winsock.exe cmd.exe no specs chcp.com no specs ping.exe no specs winsock.exe no specs systempropertiesperformance.exe no specs vnc.exe no specs svchost.exe windef.exe no specs systempropertiesperformance.exe no specs schtasks.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
296"C:\Users\admin\Desktop\Adobe Download Manager.exe"C:\Users\admin\Desktop\Adobe Download Manager.exeAdobe Download Manager.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Download Manager
Exit code:
0
Version:
...
Modules
Images
c:\users\admin\desktop\adobe download manager.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1036"C:\Users\admin\btpanui\SystemPropertiesPerformance.exe"C:\Users\admin\btpanui\SystemPropertiesPerformance.exeSystemPropertiesPerformance.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Download Manager
Exit code:
0
Version:
...
Modules
Images
c:\users\admin\btpanui\systempropertiesperformance.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1056"C:\Users\admin\AppData\Local\Temp\windef.exe" C:\Users\admin\AppData\Local\Temp\windef.exe
Adobe Download Manager.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
1.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\windef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1308C:\Windows\system32\svchost.exe -kC:\Windows\System32\svchost.exe
vnc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Host Process for Windows Services
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\psapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1432"C:\Users\admin\AppData\Local\Temp\vnc.exe" C:\Users\admin\AppData\Local\Temp\vnc.exeAdobe Download Manager.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\vnc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1528C:\Users\admin\btpanui\SystemPropertiesPerformance.exe C:\Users\admin\btpanui\SystemPropertiesPerformance.exetaskeng.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Download Manager
Exit code:
0
Version:
...
Modules
Images
c:\users\admin\btpanui\systempropertiesperformance.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
1748ping -n 10 localhost C:\Windows\System32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
1832"C:\Users\admin\AppData\Roaming\SubDir\winsock.exe"C:\Users\admin\AppData\Roaming\SubDir\winsock.exe
windef.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
1.3.0.0
Modules
Images
c:\users\admin\appdata\roaming\subdir\winsock.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Quasar
(PID) Process(1832) winsock.exe
Version1.3.0.0
C2 (3)5.8.88.191:443
sockartek.icu:443
Sub_DirSubDir
Install_Namewinsock.exe
MutexQSR_MUTEX_0kBRNrRz5TDLEQouI0
Startupwin defender run
TagEbayProfiles
LogDirLogs
Signature
Certificate
2040"C:\Users\admin\Desktop\Adobe Download Manager.exe" C:\Users\admin\Desktop\Adobe Download Manager.exe
explorer.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Download Manager
Exit code:
0
Version:
...
Modules
Images
c:\users\admin\desktop\adobe download manager.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
2052C:\Windows\system32\svchost.exe -kC:\Windows\System32\svchost.exe
vnc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Host Process for Windows Services
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\psapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
Total events
4 495
Read events
4 433
Write events
62
Delete events
0

Modification events

(PID) Process:(2040) Adobe Download Manager.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2040) Adobe Download Manager.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2040) Adobe Download Manager.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2040) Adobe Download Manager.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(296) Adobe Download Manager.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(296) Adobe Download Manager.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(296) Adobe Download Manager.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(296) Adobe Download Manager.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(296) Adobe Download Manager.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(296) Adobe Download Manager.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
4
Suspicious files
1
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2040Adobe Download Manager.exeC:\Users\admin\AppData\Local\Temp\vnc.exeexecutable
MD5:B8BA87EE4C3FC085A2FED0D839AADCE1
SHA256:4E8A99CD33C9E5C747A3CE8F1A3E17824846F4A8F7CB0631AEBD0815DB2CE3A4
1832winsock.exeC:\Users\admin\AppData\Roaming\Logs\12-21-2023binary
MD5:BB558EB00F7B493DF4E510A9A3F5B9FD
SHA256:E28B8804E14FD038C2E396C8A090D9D2164D75A6F82C6A93C4593BC2FA1EAE2C
1056windef.exeC:\Users\admin\AppData\Roaming\SubDir\winsock.exeexecutable
MD5:B4A202E03D4135484D0E730173ABCC72
SHA256:7050608D53F80269DF951D00883ED79815C060CE7678A76B5C3F6A2A985BEEA9
1832winsock.exeC:\Users\admin\AppData\Local\Temp\APuFTv6maWLm.battext
MD5:B7CDBB2A0CA50DD97800C2DC6EAF139C
SHA256:056EB1462E67469785FAD9D6703BC1FAD0B606605E5EE0AC42EE594D0B3F5AB0
2040Adobe Download Manager.exeC:\Users\admin\btpanui\SystemPropertiesPerformance.exeexecutable
MD5:7B581599D610529818B12B723574B7F3
SHA256:72C5069F262BDF5F123AB3114886C71A191AB7321EFCF65BEC123C72371A7F40
2040Adobe Download Manager.exeC:\Users\admin\AppData\Local\Temp\windef.exeexecutable
MD5:B4A202E03D4135484D0E730173ABCC72
SHA256:7050608D53F80269DF951D00883ED79815C060CE7678A76B5C3F6A2A985BEEA9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
9
DNS requests
8
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1832
winsock.exe
GET
200
208.95.112.1:80
http://ip-api.com/json/
unknown
binary
312 b
unknown
1056
windef.exe
GET
200
208.95.112.1:80
http://ip-api.com/json/
unknown
binary
312 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1308
svchost.exe
5.8.88.191:8080
PINVDS OU
RU
malicious
1056
windef.exe
208.95.112.1:80
ip-api.com
TUT-AS
US
unknown
1832
winsock.exe
208.95.112.1:80
ip-api.com
TUT-AS
US
unknown
1832
winsock.exe
5.8.88.191:443
PINVDS OU
RU
malicious
2052
svchost.exe
5.8.88.191:8080
PINVDS OU
RU
malicious

DNS requests

Domain
IP
Reputation
0x21.in
unknown
ip-api.com
  • 208.95.112.1
shared
sockartek.icu
unknown

Threats

PID
Process
Class
Message
1056
windef.exe
A Network Trojan was detected
ET MALWARE Common RAT Connectivity Check Observed
1056
windef.exe
Potential Corporate Privacy Violation
AV POLICY Internal Host Retrieving External IP Address (ip-api. com)
1056
windef.exe
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
1832
winsock.exe
A Network Trojan was detected
ET MALWARE Common RAT Connectivity Check Observed
1832
winsock.exe
Potential Corporate Privacy Violation
AV POLICY Internal Host Retrieving External IP Address (ip-api. com)
1832
winsock.exe
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
1080
svchost.exe
Potentially Bad Traffic
ET INFO DNS Query for Suspicious .icu Domain
No debug info