🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5c735b862df7042407b09e0ea339b6245239f55f84e38fedc3e58397e1cee251. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



QuasarRAT


Vendor detections: 15


Intelligence 15 IOCs YARA 9 File information Comments

SHA256 hash: 5c735b862df7042407b09e0ea339b6245239f55f84e38fedc3e58397e1cee251
SHA3-384 hash: af403d16fbe3a3e8dedd7affc458425654a51efe81f6cebed3a7421c533f3f7d9db6345b67e3a4ffcd3869e8bef76f64
SHA1 hash: f630919f67f015a6589db82dbee68f06cb3f4f86
MD5 hash: fd66b28c98eb0b7db85650dc76bcf4e6
humanhash: arizona-dakota-shade-pennsylvania
File name:Loli.bat
Download: download sample
Signature QuasarRAT
File size:9'527'623 bytes
First seen:2026-02-23 16:03:08 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/x-msdos-batch
ssdeep 49152:IZEYJGTtvz5NEYGvwACX4cXJLSnVVAIwmylqwDHLH4Imhr+6jIQ/KLQ1W6JTrBk0:w
TLSH T14EA6232B2E2934A9718A78F5817EBC979B6604310F2FFDE2C2D02756165FC540F8399B
Magika batch
Reporter abuse_ch
Tags:bat QuasarRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
SE SE
Vendor Threat Intelligence
Malware configuration found for:
BatchScript
Details
Malware family:
ID:
1
File name:
Loli.bat
Verdict:
Malicious activity
Analysis date:
2026-01-23 21:09:53 UTC
Tags:
quasar

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
97.4%
Tags:
infosteal vmdetect quasar
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching a process
Creating a file
DNS request
Using the Windows Management Instrumentation requests
Searching for synchronization primitives
Creating a file in the %temp% directory
Delayed reading of the file
Creating a process from a recently created file
Running batch commands
Creating a process with a hidden window
Creating a window
Сreating synchronization primitives
Blocking the Windows Defender launch
Unauthorized injection to a recently created process
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-23T19:20:00Z UTC
Last seen:
2026-01-23T19:55:00Z UTC
Hits:
~10
Result
Threat name:
AsyncRAT, Quasar
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus detection for dropped file
Bypasses PowerShell execution policy
Disable Windows Defender real time protection (registry)
Found large BAT file
Found malware configuration
Hides that the sample has been downloaded from the Internet (zone.identifier)
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Sigma detected: Base64 Encoded PowerShell Command Detected
Sigma detected: PowerShell Base64 Encoded FromBase64String Cmdlet
Sigma detected: Powershell Defender Disable Scan Feature
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Ping/Del Command Combination
Sigma detected: Suspicious Script Execution From Temp Folder
Suspicious powershell command line found
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Uses cmd line tools excessively to alter registry or file data
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Uses WMIC command to query system information (often done to detect virtual machines)
Yara detected AsyncRAT
Yara detected Quasar RAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1873622 Sample: Loli.bat Startdate: 23/02/2026 Architecture: WINDOWS Score: 100 84 aimbotfr-43342.portmap.host 2->84 86 Found malware configuration 2->86 88 Malicious sample detected (through community Yara rule) 2->88 90 Antivirus detection for dropped file 2->90 92 12 other signatures 2->92 14 cmd.exe 2 2->14         started        17 svchost.exe 1 1 2->17         started        signatures3 process4 dnsIp5 110 Suspicious powershell command line found 14->110 112 Uses ping.exe to sleep 14->112 114 Uses cmd line tools excessively to alter registry or file data 14->114 116 3 other signatures 14->116 20 powershell.exe 14->20         started        22 cmd.exe 1 14->22         started        25 WMIC.exe 1 14->25         started        27 18 other processes 14->27 82 127.0.0.1 unknown unknown 17->82 signatures6 process7 signatures8 29 aspozXuiZs.exe 5 20->29         started        96 Uses ping.exe to sleep 22->96 33 PING.EXE 1 22->33         started        35 PING.EXE 1 22->35         started        98 Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines) 25->98 100 Disable Windows Defender real time protection (registry) 27->100 37 MpCmdRun.exe 27->37         started        process9 file10 80 C:\Users\user\AppData\...\I68aCYidjgih.bat, DOS 29->80 dropped 118 Hides that the sample has been downloaded from the Internet (zone.identifier) 29->118 39 cmd.exe 1 29->39         started        42 conhost.exe 37->42         started        signatures11 process12 signatures13 104 Uses ping.exe to sleep 39->104 44 aspozXuiZs.exe 4 39->44         started        48 conhost.exe 39->48         started        50 PING.EXE 1 39->50         started        52 chcp.com 1 39->52         started        process14 file15 78 C:\Users\user\AppData\...\xf5e6A0ohPY2.bat, DOS 44->78 dropped 108 Hides that the sample has been downloaded from the Internet (zone.identifier) 44->108 54 cmd.exe 44->54         started        signatures16 process17 signatures18 102 Uses ping.exe to sleep 54->102 57 aspozXuiZs.exe 54->57         started        61 conhost.exe 54->61         started        63 chcp.com 54->63         started        65 PING.EXE 54->65         started        process19 file20 76 C:\Users\user\AppData\...\3cf2Xguxs6hx.bat, DOS 57->76 dropped 106 Hides that the sample has been downloaded from the Internet (zone.identifier) 57->106 67 cmd.exe 57->67         started        signatures21 process22 signatures23 94 Uses ping.exe to sleep 67->94 70 conhost.exe 67->70         started        72 chcp.com 67->72         started        74 PING.EXE 67->74         started        process24
Threat name:
Script-BAT.Trojan.Heuristic
Status:
Malicious
First seen:
2026-01-23 21:10:07 UTC
File Type:
Text (Batch)
AV detection:
5 of 24 (20.83%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:quasar botnet:onichan~ defense_evasion discovery evasion execution spyware trojan
Behaviour
Runs ping.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Network Configuration Discovery: Internet Connection Discovery
Launches sc.exe
Enumerates processes with tasklist
Checks computer location settings
Disables service(s)
Executes dropped EXE
Stops running service(s)
Command and Scripting Interpreter: PowerShell
Modifies Windows Defender DisableAntiSpyware settings
Modifies Windows Defender Real-time Protection settings
Quasar RAT
Quasar family
Quasar payload
Windows security bypass
Malware Config
C2 Extraction:
aimbotfr-43342.portmap.host:43342
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CMD_Ping_Localhost
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:detect_powershell
Author:daniyyell
Description:Detects suspicious PowerShell activity related to malware execution
Rule name:Disable_Defender
Author:iam-py-test
Description:Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:telebot_framework
Author:vietdx.mb
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques
Rule name:Warp
Author:Seth Hardy
Description:Warp
Rule name:WarpStrings
Author:Seth Hardy
Description:Warp Identifying Strings

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments