MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6a1f96c01248dad26114cabada90b8278100c458b93b15c17bd0ba894423a11c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



QuasarRAT


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 6a1f96c01248dad26114cabada90b8278100c458b93b15c17bd0ba894423a11c
SHA3-384 hash: cb1b60b3331245ef8bfcd68b45fcdbeb1b59f622b3a78f07756cfc805722d2b8f61178fc9a61aaf285474bba1dfe106a
SHA1 hash: 3e6fc64a96d7a35581bfc6c1754ae3940c63f77e
MD5 hash: 4a7404c7ef105ddfc300bcfa29d39878
humanhash: kilo-spaghetti-football-fanta
File name:Quote_13940007.rar
Download: download sample
Signature QuasarRAT
File size:369'204 bytes
First seen:2021-02-23 07:15:20 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:ZsidSPiY/9ya1ar+Jl8Cj9ZYG+FUX9ucdQr+4nUyIWw/qBRd7VXt4B/I07U:rKiY/9hw8ll9Oh+9T4Kj/qDXte/s
TLSH 4E7423E0A4592A95FF50FCC3DB3DA7B9B0A3B5205B0DD8242E8CC895B201DB503DA79D
Reporter abuse_ch
Tags:QuasarRAT rar Telegram


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: walden3d.com
Sending IP: 209.33.250.74
From: Peter Shaerf <peters.haerf@walden3d.com>
Subject: RFQ FOR Vadatech #MEM-EMMC064G
Attachment: Quote_13940007.rar (contains "Quote_13940007.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-02-23 07:16:09 UTC
AV detection:
12 of 47 (25.53%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

QuasarRAT

rar 6a1f96c01248dad26114cabada90b8278100c458b93b15c17bd0ba894423a11c

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments