Advent of Configuration Extraction – Part 2: Unwrapping QuasarRAT’s Configuration
ID: 2a812428-d435-5125-a6cd-12b2b4abecb7
STIX ID: report--2a812428-d435-5125-a6cd-12b2b4abecb7
Feed Name: Sekoia.io Blog
Date Published: 2025-12-08
Date Updated: 2026-04-29
Author: Pierre Le Bourhis, Sekoia TDR and Jeremy Scion
This report presents a reproducible, technical walkthrough for extracting QuasarRAT configuration from .NET binaries — covering lab setup (pythonnet, dnlib, Jupyter), IL inspection of the Config.Settings class, static constructor parsing, and handling obfuscated builds by locating Aes256, extracting hardcoded salt, deriving AES keys (PBKDF2), and decrypting embedded C2 and other settings; it includes code examples, analysis tips (PowerShell reflection), and a sample SHA-256 for a tested build.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
