DILLWEED
Description
(Cylance) QuasarRAT is a lightweight remote administration tool written in C#. It can collect system information, download and execute applications, upload files, log keystrokes, grab screenshots/camera captures, retrieve system passwords and run shell commands. The remote access Trojan (RAT) is loaded by a bespoke loader (a.k.a. DILLWEED). The encrypted QuasarRAT payload is stored in the Microsoft.NET directory, decrypted into memory, and instantiated using a CLR host application. In later variants an additional component is also used to install the RAT as a service (a.k.a DILLJUICE).
Names
Name |
---|
DILLWEED |
Category
Malware
Type
- Loader
Information
Other Information
Uuid
6b35dce4-3aa4-4754-8bd1-27f6a77fc395
Last Card Change
2020-04-20