MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 6a1f96c01248dad26114cabada90b8278100c458b93b15c17bd0ba894423a11c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
QuasarRAT
Vendor detections: 5
| SHA256 hash: | 6a1f96c01248dad26114cabada90b8278100c458b93b15c17bd0ba894423a11c |
|---|---|
| SHA3-384 hash: | cb1b60b3331245ef8bfcd68b45fcdbeb1b59f622b3a78f07756cfc805722d2b8f61178fc9a61aaf285474bba1dfe106a |
| SHA1 hash: | 3e6fc64a96d7a35581bfc6c1754ae3940c63f77e |
| MD5 hash: | 4a7404c7ef105ddfc300bcfa29d39878 |
| humanhash: | kilo-spaghetti-football-fanta |
| File name: | Quote_13940007.rar |
| Download: | download sample |
| Signature | QuasarRAT |
| File size: | 369'204 bytes |
| First seen: | 2021-02-23 07:15:20 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 6144:ZsidSPiY/9ya1ar+Jl8Cj9ZYG+FUX9ucdQr+4nUyIWw/qBRd7VXt4B/I07U:rKiY/9hw8ll9Oh+9T4Kj/qDXte/s |
| TLSH | 4E7423E0A4592A95FF50FCC3DB3DA7B9B0A3B5205B0DD8242E8CC895B201DB503DA79D |
| Reporter | |
| Tags: | QuasarRAT rar Telegram |
abuse_ch
Malspam distributing unidentified malware:HELO: walden3d.com
Sending IP: 209.33.250.74
From: Peter Shaerf <peters.haerf@walden3d.com>
Subject: RFQ FOR Vadatech #MEM-EMMC064G
Attachment: Quote_13940007.rar (contains "Quote_13940007.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-02-23 07:16:09 UTC
AV detection:
12 of 47 (25.53%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Kryptik
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.