logo

Advent of Configuration Extraction – Part 2: Unwrapping QuasarRAT’s Configuration

ID: 2a812428-d435-5125-a6cd-12b2b4abecb7

STIX ID: report--2a812428-d435-5125-a6cd-12b2b4abecb7

Feed Name: Sekoia.io Blog

Threat Score
65/100

Date Published: 2025-12-08

Date Updated: 2026-04-29

Author: Pierre Le Bourhis, Sekoia TDR and Jeremy Scion

...
...

This report presents a reproducible, technical walkthrough for extracting QuasarRAT configuration from .NET binaries — covering lab setup (pythonnet, dnlib, Jupyter), IL inspection of the Config.Settings class, static constructor parsing, and handling obfuscated builds by locating Aes256, extracting hardcoded salt, deriving AES keys (PBKDF2), and decrypting embedded C2 and other settings; it includes code examples, analysis tips (PowerShell reflection), and a sample SHA-256 for a tested build.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.