Quasar RAT Delivered Through Bat Files, (Wed, Jun 11th)
ID: 1a796e85-9bca-571d-8f1e-189fac2a95ea
STIX ID: report--1a796e85-9bca-571d-8f1e-189fac2a95ea
Feed Name: SANS ISC Diary
Threat Score
This report analyzes an obfuscated Windows batch/PowerShell second-stage loader used to deliver the Quasar remote access trojan (RAT). The infection uses a decoy Office document to lure victims, performs an anti-sandbox disk-name check, downloads a PNG containing an encrypted payload which is decrypted and injected into a process, and establishes persistence via a scheduled task; the report includes indicators such as a SHA256 hash, download URLs, and a C2 domain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
