ATT&CKReferencesCISA AR18-352A Quasar RAT December 2018

CISA AR18-352A Quasar RAT December 2018

CISA. (2018, December 18). Analysis Report (AR18-352A) Quasar Open-Source Remote Administration Tool. Retrieved August 1, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1005
Data from Local System
ToolQuasarRAT

QuasarRAT can retrieve files from compromised client machines.

T1016
System Network Configuration Discovery
ToolQuasarRAT

QuasarRAT has the ability to enumerate the Wide Area Network (WAN) IP through requests to ip-api[.]com, freegeoip[.]net, or api[.]ipify[.]org observed with user-agent string `Mozilla/5.0 (Windows NT 6.3; rv:48.0) Gecko/20100101 Firefox/48.0`.

T1033
System Owner/User Discovery
ToolQuasarRAT

QuasarRAT can enumerate the username and account type.

T1053.005
Scheduled Task
ToolQuasarRAT

QuasarRAT contains a .NET wrapper DLL for creating and managing scheduled tasks for maintaining persistence upon reboot.

T1059.003
Windows Command Shell
ToolQuasarRAT

QuasarRAT can launch a remote shell to execute commands on the victim’s machine.

T1095
Non-Application Layer Protocol
ToolQuasarRAT

QuasarRAT can use TCP for C2 communication.

T1112
Modify Registry
ToolQuasarRAT

QuasarRAT has a command to edit the Registry on the victim’s machine.

T1547.001
Registry Run Keys / Startup Folder
ToolQuasarRAT

If the QuasarRAT client process does not have administrator privileges it will add a registry key to `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` for persistence.

T1548.002
Bypass User Account Control
ToolQuasarRAT

QuasarRAT can generate a UAC pop-up Window to prompt the target user to run a command as the administrator.

T1564.001
Hidden Files and Directories
ToolQuasarRAT

QuasarRAT has the ability to set file attributes to "hidden" to hide files from the compromised user's view in Windows File Explorer.

T1564.003
Hidden Window
ToolQuasarRAT

QuasarRAT can hide process windows and make web requests invisible to the compromised user. Requests marked as invisible have been sent with user-agent string `Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit/537.75.14 (KHTML, like Gecko) Version/7.0.3 Safari/7046A194A` though QuasarRAT can only be run on Windows systems.

T1571
Non-Standard Port
ToolQuasarRAT

QuasarRAT can use port 4782 on the compromised host for TCP callbacks.

T1573.001
Symmetric Cryptography
ToolQuasarRAT

QuasarRAT uses AES with a hardcoded pre-shared key to encrypt network communication.

T1614
System Location Discovery
ToolQuasarRAT

QuasarRAT can determine the country a victim host is located in.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.