CISA. (2018, December 18). Analysis Report (AR18-352A) Quasar Open-Source Remote Administration Tool. Retrieved August 1, 2022.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
ToolQuasarRAT | QuasarRAT can retrieve files from compromised client machines. |
| T1016 System Network Configuration Discovery |
ToolQuasarRAT | QuasarRAT has the ability to enumerate the Wide Area Network (WAN) IP through requests to ip-api[.]com, freegeoip[.]net, or api[.]ipify[.]org observed with user-agent string `Mozilla/5.0 (Windows NT 6.3; rv:48.0) Gecko/20100101 Firefox/48.0`. |
| T1033 System Owner/User Discovery |
ToolQuasarRAT | QuasarRAT can enumerate the username and account type. |
| T1053.005 Scheduled Task |
ToolQuasarRAT | QuasarRAT contains a .NET wrapper DLL for creating and managing scheduled tasks for maintaining persistence upon reboot. |
| T1059.003 Windows Command Shell |
ToolQuasarRAT | QuasarRAT can launch a remote shell to execute commands on the victim’s machine. |
| T1095 Non-Application Layer Protocol |
ToolQuasarRAT | QuasarRAT can use TCP for C2 communication. |
| T1112 Modify Registry |
ToolQuasarRAT | QuasarRAT has a command to edit the Registry on the victim’s machine. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolQuasarRAT | If the QuasarRAT client process does not have administrator privileges it will add a registry key to `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` for persistence. |
| T1548.002 Bypass User Account Control |
ToolQuasarRAT | QuasarRAT can generate a UAC pop-up Window to prompt the target user to run a command as the administrator. |
| T1564.001 Hidden Files and Directories |
ToolQuasarRAT | QuasarRAT has the ability to set file attributes to "hidden" to hide files from the compromised user's view in Windows File Explorer. |
| T1564.003 Hidden Window |
ToolQuasarRAT | QuasarRAT can hide process windows and make web requests invisible to the compromised user. Requests marked as invisible have been sent with user-agent string `Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit/537.75.14 (KHTML, like Gecko) Version/7.0.3 Safari/7046A194A` though QuasarRAT can only be run on Windows systems. |
| T1571 Non-Standard Port |
ToolQuasarRAT | QuasarRAT can use port 4782 on the compromised host for TCP callbacks. |
| T1573.001 Symmetric Cryptography |
ToolQuasarRAT | QuasarRAT uses AES with a hardcoded pre-shared key to encrypt network communication. |
| T1614 System Location Discovery |
ToolQuasarRAT | QuasarRAT can determine the country a victim host is located in. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.