🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 003914b20f0dbbfd75c591beb26e72b75cf6a69e94b88d4e15a23d19c14fb346. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



QuasarRAT


Vendor detections: 12


Intelligence 12 IOCs YARA File information Comments

SHA256 hash: 003914b20f0dbbfd75c591beb26e72b75cf6a69e94b88d4e15a23d19c14fb346
SHA3-384 hash: 972e9fffcded6a774b8a2a25e8cd22bd8d2fd8a9885b452d4e50767ee58a715e925495db94f4375be487920b6c3493c9
SHA1 hash: 2af1ee6ff44c521e325897f3e0e9ee69adffa0aa
MD5 hash: adca4df1b1680a45db8b65ad8384298e
humanhash: tennessee-massachusetts-louisiana-uranus
File name:boss.bat
Download: download sample
Signature QuasarRAT
File size:495 bytes
First seen:2026-09-12 13:06:11 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/x-msdos-batch
ssdeep 12:E81kUM8YFEqROprI7AC9ivFU1AwbAjHFU1A2uAe3FU1AycAgoazA2h88A2UQ:cD8Y+M4ckC9mS1AjjS1A2Ze3S1Autazj
TLSH T193F0595F815D31774B23CE14CB480B8AF1BB928148D12A09B1302C19E981E4B63ED6EF
Magika batch
Reporter abuse_ch
Tags:bat QuasarRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Malware family:
ID:
1
File name:
bat
Verdict:
Malicious activity
Analysis date:
2026-09-12 13:11:59 UTC
Tags:
powershell loader auto-reg evasion quasar ahk

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug anti-vm base64 cmd crypto evasive fingerprint keylogger lolbin persistence powershell reconnaissance
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-09-12T07:42:00Z UTC
Last seen:
2026-09-13T08:15:00Z UTC
Hits:
~100
Result
Threat name:
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
Creates an autostart registry key pointing to binary in C:\Windows
Creates multiple autostart registry keys
Encrypted powershell cmdline option found
Hides that the sample has been downloaded from the Internet (zone.identifier)
Installs a global keyboard hook
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample or dropped binary is a compiled AutoHotkey binary
Sample uses string decryption to hide its real strings
Sigma detected: Files With System Process Name In Unsuspected Locations
Sigma detected: Potentially Suspicious Malware Callback Communication
Suricata IDS alerts for network traffic
Suspicious execution chain found
Suspicious powershell command line found
Yara detected PersistenceViaHiddenTask
Yara detected Quasar RAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1972240 Sample: boss.bat Startdate: 12/09/2026 Architecture: WINDOWS Score: 100 92 ipwho.is 2->92 114 Suricata IDS alerts for network traffic 2->114 116 Malicious sample detected (through community Yara rule) 2->116 118 Antivirus detection for URL or domain 2->118 120 7 other signatures 2->120 12 cmd.exe 1 2->12         started        15 SecurityHealthService.exe 2->15         started        17 SecurityHealthService.exe 2->17         started        19 3 other processes 2->19 signatures3 process4 signatures5 136 Suspicious powershell command line found 12->136 138 Encrypted powershell cmdline option found 12->138 21 powershell.exe 12 12->21         started        24 conhost.exe 12->24         started        140 Sample or dropped binary is a compiled AutoHotkey binary 15->140 26 SecurityHealthService.exe 15->26         started        28 SecurityHealthService.exe 15->28         started        34 3 other processes 15->34 36 5 other processes 17->36 30 powershell.exe 19->30         started        32 powershell.exe 19->32         started        38 7 other processes 19->38 process6 signatures7 128 Suspicious execution chain found 21->128 40 cmd.exe 1 21->40         started        130 Installs a global keyboard hook 24->130 132 Sample or dropped binary is a compiled AutoHotkey binary 26->132 42 cmd.exe 30->42         started        45 cmd.exe 32->45         started        process8 signatures9 47 svc.exe 15 13 40->47         started        52 cmd.exe 1 40->52         started        54 conhost.exe 40->54         started        64 4 other processes 40->64 134 Encrypted powershell cmdline option found 42->134 56 conhost.exe 42->56         started        58 powershell.exe 42->58         started        60 conhost.exe 45->60         started        62 powershell.exe 45->62         started        process10 dnsIp11 96 ipwho.is 172.66.175.107, 443, 49719 CLOUDFLARENET-CloudflareIncUS Canada 47->96 88 C:\Users\user\...\SecurityHealthService.exe, PE32+ 47->88 dropped 100 Creates multiple autostart registry keys 47->100 102 Hides that the sample has been downloaded from the Internet (zone.identifier) 47->102 104 Installs a global keyboard hook 47->104 106 Sample or dropped binary is a compiled AutoHotkey binary 47->106 66 svc.exe 47->66         started        69 svc.exe 47->69         started        71 svc.exe 47->71         started        77 2 other processes 47->77 108 Suspicious powershell command line found 52->108 73 powershell.exe 12 52->73         started        75 conhost.exe 52->75         started        98 31.56.209.11, 49703, 49704, 49705 SWISSNET-ASUS Netherlands 64->98 90 C:\Users\user\AppData\Local\Temp\svc.exe, PE32+ 64->90 dropped file12 signatures13 process14 signatures15 110 Sample or dropped binary is a compiled AutoHotkey binary 66->110 79 cmd.exe 1 73->79         started        112 Installs a global keyboard hook 75->112 process16 signatures17 142 Encrypted powershell cmdline option found 79->142 82 powershell.exe 1 18 79->82         started        86 conhost.exe 79->86         started        process18 dnsIp19 94 217.60.195.226, 4782, 49709, 49716 NETPOOLIN Netherlands 82->94 122 Creates multiple autostart registry keys 82->122 124 Creates an autostart registry key pointing to binary in C:\Windows 82->124 126 Installs a global keyboard hook 86->126 signatures20
Threat name:
Script-BAT.Dropper.Heuristic
Status:
Malicious
First seen:
2026-09-12 12:59:58 UTC
File Type:
Text (Batch)
AV detection:
6 of 36 (16.67%)
Threat level:
  2/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

QuasarRAT

Batch (bat) bat 003914b20f0dbbfd75c591beb26e72b75cf6a69e94b88d4e15a23d19c14fb346

(this sample)

  
Delivery method
Distributed via web download

Comments