Threat Database Backdoors Backdoor.Quasar.BB

Backdoor.Quasar.BB

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 13,665
Threat Level: 60 % (Medium)
Infected Computers: 67
First Seen: April 4, 2025
Last Seen: July 6, 2026
OS(es) Affected: Windows

The detection of Backdoor.Quasar.BB on your system indicates a potential security threat that requires immediate attention. This detection name suggests a backdoor threat, which is a type of malware that allows unauthorized access to a computer system. In this report, we will provide an overview of what Backdoor.Quasar.BB is, how it operates, the symptoms of infection, and the steps you can take to remove it from your system.

What Is Backdoor.Quasar.BB?

A backdoor is a type of malware that creates a secret entrance to a computer system, allowing an attacker to access the system without being detected. Backdoors can be used to steal sensitive information, install additional malware, or take control of the system. The name Backdoor.Quasar.BB does not provide specific information about the malware family or its origins, but it suggests that it is a backdoor threat that can potentially cause harm to your system.

How Backdoor.Quasar.BB Operates

Backdoor malware, including Backdoor.Quasar.BB, typically operates by creating a connection between the infected system and a command and control (C2) server. This connection allows the attacker to send commands to the infected system, steal sensitive information, or install additional malware. Backdoors can be spread through various means, including phishing emails, infected software downloads, or exploited vulnerabilities. Once installed, the backdoor can remain hidden on the system, making it difficult to detect and remove.

Symptoms of Infection

The symptoms of a backdoor infection can be subtle, but they may include unusual system behavior, such as slow performance, unexpected crashes, or unfamiliar programs running in the background. You may also notice that your system is connecting to unfamiliar servers or that your sensitive information is being stolen. However, in many cases, backdoor infections can remain hidden, making it essential to use antivirus software and regularly scan your system for potential threats.

How to Remove Backdoor.Quasar.BB

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Use a reputable antivirus tool, such as SpyHunter, to perform a full scan of your system and detect any malware, including Backdoor.Quasar.BB.
  3. Uninstall any suspicious programs or applications that may be related to the backdoor infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings.
  5. Reboot your system and perform another scan with your antivirus tool to ensure that the malware has been completely removed.

Conclusion

The detection of Backdoor.Quasar.BB on your system is a serious security threat that requires immediate attention. By understanding how backdoor malware operates and taking the necessary steps to remove it, you can protect your system and sensitive information from potential harm. Remember to always use reputable antivirus software, regularly scan your system for potential threats, and practice safe computing habits to minimize the risk of infection. If you are unsure about how to remove Backdoor.Quasar.BB or if you need additional assistance, consider consulting with a cybersecurity professional or seeking help from a trusted security resource.

Analysis Report

General information

Family Name: Backdoor.Quasar.BB
Signature status: No Signature

Known Samples

MD5: 7b47639530528a9f06cbea830b31f62d
SHA1: fec342f4705a1f4751230dab741c3e27208c71b8
SHA256: 87DA853EEAEF7E7B360930E878FD8BAAFB681E0A969F2F84C9483C498501080F
File Size: 992.26 KB, 992256 bytes
MD5: 0d1e20c4d40f8fbb8570d8610c18b7c5
SHA1: 066dde1a5c03ed8898a42a495b5a623c69b4b96e
SHA256: 64BFB8E28F421328D917945E6F69E0F0CC66138FEBEEC2DB9FFBBCEFCE1D6064
File Size: 1.76 MB, 1763880 bytes
MD5: 07f8ae61faaf6e076cdaeee6ef71c729
SHA1: 2fabc0d3a656fbc2f2c01458f20d1511e89294d8
SHA256: 3ECF1FCC7AC7AA26030D6269C4299CF4FC135DAA62D8FF6A70A16FC83449A07F
File Size: 708.10 KB, 708096 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description
  • Microsoft Sync Center
  • Microsoft® HTML Help Executable
  • Remote Access Dialer
File Version
  • 10.0.19041.4355 (WinBuild.160101.0800)
  • 10.0.19041.3636 (WinBuild.160101.0800)
  • 10.0.19041.1 (WinBuild.160101.0800)
Internal Name
  • HH 1.41
  • mobsync.exe
  • rasdlui.exe
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename
  • HH.exe
  • mobsync.exe
  • rasdlui.exe
Product Name
  • HTML Help
  • Microsoft® Windows® Operating System
Product Version
  • 10.0.19041.4355
  • 10.0.19041.3636
  • 10.0.19041.1

Digital Signatures

Signer Root Status
NVIDIA Corporation DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch

File Traits

  • 2+ executable sections
  • HighEntropy
  • x64

Block Information

Total Blocks: 2,675
Potentially Malicious Blocks: 1,070
Whitelisted Blocks: 1,391
Unknown Blocks: 214

Visual Map

? x ? x 0 ? 0 0 x x x x x x 0 x x 0 x x 0 x x x 0 x x 0 x 0 0 0 0 ? x 0 x 0 0 0 0 x x x x x x x x x x ? x 0 x 0 0 0 0 x x 0 x ? 0 0 0 x x x 0 x ? x x x 0 x x x x x x x x x 0 ? x x ? ? x ? ? x ? x ? x 0 0 x 0 x ? 0 x 0 x ? 0 x 0 x ? 0 x 0 0 0 x 0 ? x ? x x x x x x x ? x ? x ? 0 ? x 0 x 0 x x x x 0 0 0 0 x ? ? 0 x ? 0 x 0 ? x x x 0 x x x 0 0 x 0 0 0 x x 0 0 0 x x 0 0 0 x 0 ? x x 0 x 0 x ? x x 0 x x x ? x x 0 x x ? x x x 0 x 0 0 0 0 x 0 0 ? ? 0 0 x x x ? x 0 0 0 x 0 ? 0 x x x 0 0 x 0 x ? ? x x 0 x x x 0 x x 0 0 x x ? x x x x x x x x ? x x 0 0 x 0 x x x x x 0 x x x x x x x 0 0 0 0 x 0 x x x x x x x ? 0 0 x 0 0 x 0 0 x 0 x ? 0 0 x 0 0 x 0 x ? 0 0 x 0 0 x 0 ? 0 0 x 0 0 x 0 0 0 x ? 0 0 x 0 0 x 0 ? 0 0 x 0 0 x 0 ? ? 0 0 x 0 0 x 0 ? ? 0 x x x 0 0 x x x x 0 x x x 0 x x x x x x x x x x x 0 x x x x x x x x x x x x x 0 x x 0 ? x x x x x x x 0 x x x x x x 0 0 0 x x 0 x 0 0 x 0 x 0 0 x x x 0 0 x 0 x 0 0 x 0 0 x 0 x 0 0 x 0 0 x 0 x 0 0 x 0 0 x 0 x 0 0 x 0 0 x 0 x 0 0 x 0 0 x 0 x 0 0 x 0 0 x 0 x 0 0 x ? 0 x 0 x x x 0 x x 0 0 x 0 0 x x x x x x ? 0 0 x 0 0 x 0 0 x 0 x ? 0 0 x 0 0 x 0 x ? 0 0 x 0 0 x 0 ? 0 0 x 0 0 x 0 0 0 x ? 0 0 x 0 0 x 0 ? 0 0 x 0 0 x 0 ? ? 0 0 x 0 0 x 0 ? ? x x 0 0 0 x x x x 0 x x 0 x x 0 x x x x x x ? x x x 0 x x x 0 0 x x x x x x x x x x 0 0 x x x x x x x x x x 0 x x 0 0 x 0 x 0 x x x x 0 x ? x ? 0 x ? x 0 x x 0 x ? x ? 0 x ? x 0 x x ? ? 0 0 x x x 0 0 x 0 x x 0 0 x x x 0 0 x x x x x x x x x x x x ? x x x 0 x 0 x x ? x x x 0 x 0 x x x x x 0 x x 0 x x 0 x x x 0 x x 0 x x 0 x ? ? 0 0 ? x x x x x 0 x 0 x 0 x x ? x 0 x x ? x 0 x x ? 0 x 0 0 x x 0 x 0 0 0 ? ? x x x x ? x 0 x 0 ? x 0 x 0 0 x x x x x x 0 0 x 0 x x x 0 0 0 x 0 x ? ? x x 0 0 0 ? x x 0 ? ? ? x x x 0 x 0 0 x x x 0 0 0 x x 0 x x 0 0 x x 0 x 0 0 x x x x 0 x x 0 x x 0 0 ? x 0 x 0 x ? ? x 0 x 0 0 0 x 0 x x 0 0 0 0 x 0 0 x x 0 0 x x x x 0 x x 0 x 0 x x 0 x 0 0 ? ? x x x 0 0 0 0 0 x x x 0 0 0 x x x 0 0 0 x x x x x x 0 0 0 x x x 0 0 0 x x x 0 0 0 x x x 0 0 0 x x x 0 0 0 x x x 0 0 0 x x ? 0 0 0 x x ? 0 0 0 x x ? 0 0 0 x x 0 x 0 0 ? 0 0 0 x x ? 0 0 0 x x ? 0 0 0 x x 0 x 0 x x 0 0 0 x x x 0 0 0 x x x 0 0 x 0 0 0 x x ? 0 0 0 x x 0 x x x x 0 x 0 x 0 0 0 0 0 x 0 x x x 0 0 0 x x x x x 0 x 0 0 0 0 0 x 0 x 0 0 0 0 0 x x 0 0 0 x x x 0 0 0 x x 0 0 ? 0 ? x x x 0 ? 0 0 0 x x x 0 0 0 x x x 0 0 0 x x x 0 0 0 x x 0 x 0 x x 0 0 x 0 0 0 x 0 x x 0 0 x ? x ? ? x ? x x 0 x x ? x 0 x x 0 x x 0 x x x 0 x x 0 x 0 0 x x x x x x x x 0 x 0 x ? 0 x ? x 0 x 0 x x ? 0 x 0 x x x 0 0 0 ? x ? ? x x x x x 0 0 x x x ? x 0 0 x ? ? 0 x ? x x 0 x 0 x ? x 0 0 x x ? x 0 0 x ? 0 ? x ? 0 x 0 x ? x 0 0 x x x ? 0 0 ? 0 x x 0 0 0 0 x 0 x x 0 x x x x 0 x x x x x x 0 0 x 0 0 x 0 x x x x 0 ? 0 0 x 0 x 0 ? x x x 0 x 0 x ? x 0 x 0 0 x 0 x x x x x x x 0 x x x 0 x x ? ? ? 0 0 x x x x x 0 x x 0 x 0 0 0 x x x x x 0 x 0 x 0 x 0 0 x 0 x 0 1 1 x x ? 0 0 x x x x x ? 0 ? x x 0 x 0 0 0 x x x ? x x x 0 x 0 0 0 0 0 x 0 0 x 0 0 x x x ? x 0 x x 0 x x 0 x x x 0 x 0 x x x x x 0 0 0 x 0 ? x ? x x 0 x 0 0 x x 0 ? x x 0 0 0 x 0 0 0 ? 0 x x ? x 0 0 x x x ? x 0 0 0 ? 0 ? 0 x 0 x x x ? ? 0 0 ? x ? ? 0 x x x x 0 x x x 0 0 0 ? ? 0 ? x ? ? 0 ? 0 0 x ? ? 0 0 x ? ? ? 0 x 0 ? x ? x x 0 ? 0 x 0 x x x 0 0 ? 0 0 0 x x 0 x x x ? ? x x x 0 x x x x x x 0 x 0 0 0 x x 0 x x x 0 x ? ? 0 x 0 ? x x 0 0 x x 0 0 x x x 0 x x x 0 ? x x x x x 0 x 0 x x x 0 x 0 0 x x x x x x 0 0 x 0 x x 0 0 x x x 0 0 x x x x 0 x x x 0 x x 0 0 x x 0 x 0 0 x x 0 0 x 0 x x 0 0 x 0 x x ? ? x x x 0 0 x x x 0 x ? x 0 x x 0 0 x x x x 0 0 x x x x x 0 0 x 0 0 ? x x x 0 0 x ? x 0 0 x x 0 0 x x 0 0 x 0 0 0 0 x x 0 0 x 0 0 0 0 x 0 0 x x 0 0 x x x x x 0 x ? x 0 x x 0 0 x 0 x x x 0 x 0 0 x 0 x x 0 x x x x 0 x x x 0 x 0 x 0 x x 0 ? x x ? x x 0 0 0 0 x x 0 x 0 x x x x x 0 0 x x ? x x x x x 0 0 0 x x 0 0 x ? x x x 0 x x x 0 x 0 x 0 0 x ? x 0 0 0 ? ? x x x x x 0 0 0 ? x x 0 ? x 0 0 ? 0 x x x x x x x ? 0 0 x ? 0 0 x x 0 x 0 x ? 0 0 x x 0 0 0 x ? x x x x 0 0 ? x 0 x 0 x x x 0 0 0 x 0 0 ? x 0 0 x ? ? ? x x x x 0 0 0 0 x x x 0 0 x 0 x 0 x 0 0 x 0 x x x ? 0 x x x x 0 0 0 x 0 ? 0 x x x 0 ? x x ? 0 0 0 0 x 0 0 ? x x 0 0 ? ? 0 0 0 0 x 0 0 x 0 x ? 0 x x x 0 x ? x x ? ? ? x ? x 0 0 0 x 0 ? x x x x x 0 0 x 0 x 0 x 0 x 0 x 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • CobaltStrike.SVA

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
Show More
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Related Posts

Trending

Most Viewed

Loading...