Malicious
Classifications
Backdoor Spyware Keylogger
Threat Names
QuasarRAT xRAT Mal/Generic-S QuasarRAT.v1
Dynamic Analysis Report
Created on 2024-05-20T23:07:37+00:00
Sghgftd.exe
Windows Exe (x86-32)
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\RDhJ0CNFevzX\Desktop\Sghgftd.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Verdict |
Malicious
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004051A2 |
Size Of Code | 0x00003200 |
Size Of Initialized Data | 0x0003A400 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2022-12-25 20:59 (UTC+1) |
Version Information (7)
»
FileDescription | Sghgftd |
FileVersion | 0.0.0.0 |
InternalName | Sghgftd.exe |
LegalCopyright | |
OriginalFilename | Sghgftd.exe |
ProductVersion | 0.0.0.0 |
Assembly Version | 0.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00402000 | 0x000031A8 | 0x00003200 | 0x00000200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.47 |
.rsrc | 0x00406000 | 0x0003A1A8 | 0x0003A200 | 0x00003400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.42 |
.reloc | 0x00442000 | 0x0000000C | 0x00000200 | 0x0003D600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.08 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | - | 0x00402000 | 0x00005178 | 0x00003378 | 0x00000000 |
Memory Dumps (60)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
sghgftd.exe | 1 | 0x00FF0000 | 0x01033FFF | Relevant Image | 32-bit | - |
...
|
||
buffer | 1 | 0x00B7E000 | 0x00B7FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x00189000 | 0x0018FFFF | First Network Behavior | 32-bit | - |
...
|
||
sghgftd.exe | 1 | 0x00FF0000 | 0x01033FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x04CF0000 | 0x04D2AFFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x01380000 | 0x01381FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x056F0000 | 0x056F0FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x05700000 | 0x05700FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x05710000 | 0x05710FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x05700000 | 0x05700FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x05720000 | 0x05720FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x05730000 | 0x05730FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x05720000 | 0x05720FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x05740000 | 0x05740FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x056F0000 | 0x056F0FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x05750000 | 0x05750FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x05740000 | 0x05740FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x056F0000 | 0x056F0FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
sghgftd.exe | 1 | 0x00FF0000 | 0x01033FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 1 | 0x05770000 | 0x05770FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x05750000 | 0x05750FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x05740000 | 0x05740FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x056F0000 | 0x056F0FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x05780000 | 0x05780FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x05770000 | 0x05770FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x05750000 | 0x05750FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x05740000 | 0x05740FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x056F0000 | 0x056F0FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 7 | 0x00400000 | 0x0045DFFF | Content Changed | 32-bit | - |
...
|
||
sghgftd.exe | 7 | 0x004B0000 | 0x004F3FFF | Relevant Image | 32-bit | - |
...
|
||
sghgftd.exe | 1 | 0x00FF0000 | 0x01033FFF | Process Termination | 32-bit | - |
...
|
||
buffer | 7 | 0x04D2D000 | 0x04D2FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 7 | 0x0489C000 | 0x0489FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 7 | 0x0445E000 | 0x0445FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 7 | 0x00189000 | 0x0018FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 7 | 0x00400000 | 0x0045DFFF | First Network Behavior | 32-bit | - |
...
|
||
sghgftd.exe | 7 | 0x004B0000 | 0x004F3FFF | First Network Behavior | 32-bit | - |
...
|
||
sghgftd.exe | 9 | 0x00030000 | 0x00073FFF | Relevant Image | 32-bit | - |
...
|
||
buffer | 9 | 0x05150000 | 0x0518AFFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 9 | 0x047F0000 | 0x047F1FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 9 | 0x04990000 | 0x04990FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 9 | 0x049B0000 | 0x049B0FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 9 | 0x04B50000 | 0x04B50FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 9 | 0x04B60000 | 0x04B60FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 9 | 0x04B70000 | 0x04B70FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 9 | 0x05290000 | 0x05290FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 9 | 0x052A0000 | 0x052A0FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 9 | 0x052C0000 | 0x052C0FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 9 | 0x052D0000 | 0x052D0FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 10 | 0x00400000 | 0x0045DFFF | Content Changed | 32-bit | - |
...
|
||
sghgftd.exe | 10 | 0x00550000 | 0x00593FFF | Relevant Image | 32-bit | - |
...
|
||
sghgftd.exe | 9 | 0x00030000 | 0x00073FFF | Process Termination | 32-bit | - |
...
|
||
buffer | 10 | 0x04CFE000 | 0x04CFFFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 10 | 0x0487C000 | 0x0487FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 10 | 0x0235E000 | 0x0235FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 10 | 0x00188000 | 0x0018FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 10 | 0x00400000 | 0x0045DFFF | First Network Behavior | 32-bit | - |
...
|
||
sghgftd.exe | 10 | 0x00550000 | 0x00593FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 10 | 0x00400000 | 0x0045DFFF | Final Dump | 32-bit | - |
...
|
||
sghgftd.exe | 10 | 0x00550000 | 0x00593FFF | Final Dump | 32-bit | - |
...
|
C:\Users\RDhJ0CNFevzX\AppData\Roaming\Logs888\05-21-2024 | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Roaming\Logs888\05-21-2024 | Dropped File | Stream |
Clean
|
...
|
»