MalScore
100/100

Quasar.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 59/72 Related 2696
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 348.00 KB (356352 bytes)
Compile time: 2019-04-02 13:27:49
MD5: 78e2802f8cca7c8a810a17872c64996c
SHA1: 778ce779f7c9a0469962a8e9ca934c9e1fe90fb9
SHA256: d13bc63d0aed32358a9530705b3f5df76068b34ff2b7a981e593343c5753c5e0
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2019-05-25 00:42:05
Last submission: 2019-05-25 00:42:05
Filename detected: - Quasar.exe (1)
URL file hosting
hXXp://stahlke.ca/Quasar.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2019-05-08 07:48:34 [59/72] VirusTotal
PE Sections 1 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x561a4 352768 6fc469b15d8d1ef40c83b96f160e166b 445f69aa8d25a5e91f7809657a2aaea38d32aea7
.rsrc 0x5a000 0xa00 2560 76cc3230218ab47d3ced751a87f28c1b a12523f0acaceeb308a3631f60acd5788071738e
.reloc 0x5c000 0xc 512 68c538a9245c495540d935200299e4a5 9ce2bec8d2c1f891ca42ce0283fb47c3b05bac59
Meta Info
No Meta found in this file
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: XML
{0}\FileZilla\recentservers.xml
{0}\FileZilla\sitemanager.xml
System.Xml
FIle type: Library
\msvcp120.dll
\msvcp100.dll
\mozglue.dll
\msvcr120.dll
\nss3.dll
\msvcr100.dll
USER32.dll
KERNEL32.dll
ntdll.dll
IPHLPAPI.DLL
mscoree.dll
MSVCRT.dll
GDI32.dll
SHELL32.dll
SHLWAPI.dll
ole32.dll
ADVAPI32.dll
OLEAUT32.dll
IP Found
No IP detected
URL(s)
http://ip-api.com/json/
http://
http://api.ipify.org/
file:///
http://schemas.microsoft.com/SMI/2005/WindowsSettings
http://freegeoip.net/xml/
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2019-05-25 00:35:43 2019-05-25 00:38:43 180

0 Summary items with data

Files

Nothing to display

Read Files

Nothing to display

Write Files

Nothing to display

Delete Files

Nothing to display

Keys

Nothing to display

Read Keys

Nothing to display

Write Keys

Nothing to display

Delete Keys

Nothing to display

Mutexes

Resolved APIs

Nothing to display

Execute Commands

Nothing to display

Started Services

Nothing to display

Created Services

Nothing to display

#infosec #automation

TheSystem Itself @ 2019-05-25 00:42:07