Quasar RAT Activity January, 2021
Over the last couple days of this new year, I've seen a couple Quasar RATs come across my path. So I decided to highlight some of the analysis here. The first sample I'm looking at is invoice.iso (8fc2bdfaf329c652090d6bcd2f88b764). As you can see from the app.any.run link this ends up dropping and executing a simple VBS file. Clearly, we see that this attempts to use "MSHTA" to navigate to the minpic[.]de link pictured above. This results in the following powershell script, cleverly disguised as a JPEG file. When we run a simple base64 decoding against this we get another URL in the minpic[.]de domain called by powershell. hxxps://www.minpic[.]de/t/be5r/18jv5z. When we look at this page, we see yet another powershell script which again references another link in the minpic[.]de domain! When we look at this URL we find a page that contains a whole bunch of Hex code! The previous powershell script, which references this page of Hex code, als...