Threat Database Backdoors Backdoor.MSIL.Quasar.CB

Backdoor.MSIL.Quasar.CB

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 14,697
Threat Level: 60 % (Medium)
Infected Computers: 309
First Seen: January 10, 2024
Last Seen: May 11, 2026
OS(es) Affected: Windows

The detection of Backdoor.MSIL.Quasar.CB on a system indicates a serious security threat that requires immediate attention. This backdoor threat can compromise the integrity of a computer system, allowing unauthorized access and potentially leading to further malicious activities. It is essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is Backdoor.MSIL.Quasar.CB?

Backdoor.MSIL.Quasar.CB is a type of backdoor threat that can provide unauthorized access to a compromised system. The term "backdoor" refers to a method of bypassing normal security mechanisms to gain access to a system. This type of malware can be particularly dangerous as it can allow attackers to remotely control the infected system, steal sensitive information, or use the system for malicious purposes such as spreading spam or participating in distributed denial-of-service (DDoS) attacks.

How Backdoor.MSIL.Quasar.CB Operates

Backdoor threats like Backdoor.MSIL.Quasar.CB typically operate by creating a covert communication channel between the compromised system and a command and control (C2) server controlled by the attackers. This channel can be used to send commands to the infected system, allowing the attackers to execute malicious actions. The backdoor may also be designed to evade detection by traditional security software, making it challenging to identify and remove without specialized tools and techniques.

Symptoms of Infection

Systems infected with Backdoor.MSIL.Quasar.CB may exhibit a range of symptoms, including unusual network activity, slow system performance, and unexplained changes to system settings or files. However, in many cases, backdoor infections can remain asymptomatic, making them difficult to detect without proactive monitoring and scanning. It is crucial for users to be vigilant and regularly scan their systems for signs of infection to prevent prolonged exposure to malicious activities.

How to Remove Backdoor.MSIL.Quasar.CB

  1. Boot your system into Safe Mode with Networking to prevent the malware from loading and to allow for internet access to download removal tools.
  2. Conduct a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all components of the Backdoor.MSIL.Quasar.CB malware.
  3. Uninstall any suspicious programs that may have been installed without your knowledge or consent, as these could be linked to the backdoor infection.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings that may have been altered by the malware.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that all traces of the malware have been removed.

Conclusion

The removal of Backdoor.MSIL.Quasar.CB requires careful and systematic steps to ensure that all components of the malware are eliminated from the infected system. By understanding how backdoor threats operate and following the recommended removal procedures, users can protect their systems from these types of infections and prevent potential data breaches or other malicious activities. Regular system scans, keeping software up to date, and practicing safe computing habits are essential for maintaining system security and preventing future infections.

Analysis Report

General information

Family Name: Backdoor.MSIL.Quasar.CB
Signature status: No Signature

Known Samples

MD5: 5bfd23d919cdca24ca00fd209fb2c892
SHA1: 26ed7e77c2f0e908c44ae91583df7b7d89eb09ab
File Size: 3.27 MB, 3265536 bytes
MD5: e63e1002264bfab0984f5bbaa6b087c3
SHA1: bfd51cdb12fc254f73de42bc86d621bee7baefda
File Size: 3.27 MB, 3266048 bytes
MD5: b7a22e3a5f77693df1e60c609422e3c6
SHA1: 788806aaddb01339b9fc3565c3c639b35293be06
SHA256: 9E2C555B3A28BD2FB7DEB92BBF17DB87BBDE1ECCF67968946E0610C1DD0B1FAF
File Size: 3.27 MB, 3265536 bytes
MD5: 6d122e686eee5c07efc1b77aa8aa0964
SHA1: 6670ed216aa90152e520e2e9ac8d77182eebcaa6
SHA256: BF3B25A2B492A680410CE9E11BC6CA565421AAAB80F1544688233E4E46BE667C
File Size: 3.27 MB, 3269120 bytes
MD5: d014ed4d60a17350c71d2e5802375db1
SHA1: 06a79f2c3f05936c719c41ed9894291bedefbdd3
SHA256: 360C50039718ABA457E304430E4473FFEF01F1AAE1DEA14C26805D2BBC4235C1
File Size: 3.27 MB, 3265536 bytes
Show More
MD5: e22042f26afb819589df0c802700c19b
SHA1: dd23705275195878ef2daaefef3db67765076dda
SHA256: A01BD1832D20DE21F4F5F6B7A72987D8C83C70BE17AC8730CC67074C901C071E
File Size: 3.27 MB, 3265536 bytes
MD5: 84000533ecb2ad9cc3cc8b0ed4919393
SHA1: e2538225215ae24b4cfb52dd5825525d1b1471b7
SHA256: 4140A54E72BBB6A8E103CB109F88FE5A62B2F83735F085D9612674A17B48EF2D
File Size: 3.27 MB, 3265536 bytes
MD5: 2be09e53d5ce933bafcb0bf54143f0d3
SHA1: df7055de0aa17d40e0edbe92ac204670b68f119e
SHA256: C2FF2628B8FEF2F29D326F6B21A7EE79A4367A1066E5151FF524A0B084922A47
File Size: 3.27 MB, 3265536 bytes
MD5: f13287e4ccba22c67cb56af757086b7d
SHA1: 3e0780337841c7c9117661f057f49ccac16deb6a
SHA256: 441361AED58CCA83DDAE2000305153C4BD471D379201D7B964489148D0D3922A
File Size: 3.27 MB, 3266048 bytes
MD5: 05190a8f5edd34062bcaaa1dae84242f
SHA1: 0d5ba02e4d891b351e8aa269989feb3789ea0ad5
SHA256: 616D158A93F67CB26999D87B80FE512661E27543BDDC3973B34665EED79F1B03
File Size: 3.27 MB, 3266048 bytes
MD5: 1db43578c8364478026b17bdd87bb4ed
SHA1: d621e1797d85825c3f47d1ae59c29cdeff7007c4
SHA256: 5DF1973BF502A112E6A85E7F03F37F9529BDCE278B36AB700E37C59297D5DAA0
File Size: 3.27 MB, 3265536 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version
  • 2.1.1.4
  • 1.4.1.0
  • 1.0.0.0
Company Name Manthe Industries, LLC
File Description
  • microsoft
  • Quasar Client
File Version
  • 2.1.1.4
  • 1.4.1
  • 1.0
Internal Name
  • Client.exe
  • Spook_V2.1.1.4.exe
Legal Copyright
  • Copyright © MaxXor 2023
  • Manthe Industries, LLC
Legal Trademarks Manthe Industries, LLC
Original Filename
  • Client.exe
  • Spook_V2.1.1.4.exe
Product Name
  • Quasar
  • Spook Client
Product Version
  • 2.1.1.4
  • 1.4.1
  • 1.0

File Traits

  • .NET
  • Run
  • x86

Block Information

Total Blocks: 14,560
Potentially Malicious Blocks: 307
Whitelisted Blocks: 14,252
Unknown Blocks: 1

Visual Map

x x x x 0 0 x x x x x x x 0 0 0 x 0 x x 0 x x x 0 x x 0 x x x x 0 x x x 0 x x x x x x x x x x x x x x 0 0 x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x 0 x x x 0 x x x 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x x x x x x x x x x 0 x 0 x x x x 0 0 0 0 0 x x x x x 0 x x x x x x x x x 0 x 0 x 0 0 0 0 x 0 0 x x 0 0 x x x x x x x x x x x 0 x x x x x 0 0 0 x 0 0 x 0 0 0 0 x 0 x x 0 0 x 0 x x x x 0 x 0 0 x x x 0 x x x x x x 0 x 0 x x x x 0 0 x x 0 0 x 0 0 x x x x x 0 x 0 0 0 0 x x x x x x x x x x x x 0 0 0 0 x x x x x x x x 0 x x x x x x x x 0 x x x x 0 x x x 0 x x x x x x x x x x 0 x x x 0 x x x 0 x 0 x x 0 x x x x 0 x x x x x 0 x x 0 0 0 x 0 0 0 0 x 0 0 x x x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x x x 0 0 x x x x 0 x x x x 0 x 0 0 x 0 x 0 0 0 x x 0 x 0 x 0 0 0 0 x x x x 0 0 0 x x x x 0 0 0 0 x 0 0 x x 0 x x 0 x x x x 0 x x x x 0 x x 0 x x x x 0 x 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Mardom.SF
  • MSIL.Quasar.B
  • MSIL.Quasar.CA
  • MSIL.Quasar.CB
  • MSIL.Spy.RC
Show More
  • MSIL.Spy.RCB

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • IsDebuggerPresent
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext

Related Posts

Trending

Most Viewed

Loading...