MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a9b53acfb1fdca1885e5b2c3bbb68d558f237a68f033c594e0cf1120cf65b115. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



QuasarRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a9b53acfb1fdca1885e5b2c3bbb68d558f237a68f033c594e0cf1120cf65b115
SHA3-384 hash: 67559a469722ed71af721b92bb5133851471ebca80747d377d6c3b15c06294ee1e7cb99cf7ac66eb721416e312081512
SHA1 hash: 7d0c6ff038b0b2b05b2d3f2c334850ede993e7dd
MD5 hash: 0f638a7c6c2a8602cf629e0eaf351282
humanhash: lemon-shade-connecticut-bacon
File name:ZY44.ISO
Download: download sample
Signature QuasarRAT
File size:55'296 bytes
First seen:2020-12-20 12:08:51 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 48:5RuSt2sK2m+LF9f5Hu04dSYQIZas43dMUVMoxOPlO:52sKL+L3fydSYQIZas43d9Rq
TLSH 6D4382C8161FE4F4F816E070345FEBA7C663AA5734F16111FB8E8AA0877F215A135396
Reporter abuse_ch
Tags:HostGator iso QuasarRAT


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: gateway24.websitewelcome.com
Sending IP: 192.185.50.71
From: TheBill <Invoice69@Mail10.homebill.xzp.fr>
Subject: Order Confirmation.
Attachment: ZY44.ISO (contains "ZY44.vbs")

Intelligence


File Origin
# of uploads :
1
# of downloads :
448
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Threat name:
Script-WScript.Trojan.Heuristic
Status:
Malicious
First seen:
2020-12-20 12:09:08 UTC
AV detection:
3 of 48 (6.25%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

QuasarRAT

iso a9b53acfb1fdca1885e5b2c3bbb68d558f237a68f033c594e0cf1120cf65b115

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments