MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 b475cc4daadb077b75d0d5924e34c75fa179e17b38a1cbd0366a3290ed7ac422. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
QuasarRAT
Vendor detections: 19
| SHA256 hash: | b475cc4daadb077b75d0d5924e34c75fa179e17b38a1cbd0366a3290ed7ac422 |
|---|---|
| SHA3-384 hash: | 6a2e6261556855ba66115aa264a46e7fe013ec5fab61ef73964f6bebc0b97e03ec64f2bdc14001664013242b3af15fd2 |
| SHA1 hash: | 4223ff7e3077270891d03b06498fd3ad6aefb0cc |
| MD5 hash: | d2e366fcb0c9d31bb53bcf7cfffb2b9b |
| humanhash: | fourteen-ack-saturn-mobile |
| File name: | file |
| Download: | download sample |
| Signature | QuasarRAT |
| File size: | 2'032'640 bytes |
| First seen: | 2025-10-20 04:04:24 UTC |
| Last seen: | 2025-10-21 04:05:10 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'748 x AgentTesla, 19'646 x Formbook, 12'245 x SnakeKeylogger) |
| ssdeep | 49152:GM83d1O5RtVbBUflo3UDhfEC3lWmoBqP3NI1lyDXYO3b:U3/0VbCE8W5cOlyDXXb |
| Threatray | 242 similar samples on MalwareBazaar |
| TLSH | T1059533743090409AD31FE870769AF98D276AED474079363703B44DAF22C72BDAB95D36 |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10522/11/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| Reporter | |
| Tags: | dropped-by-amadey exe QuasarRAT |
Intelligence
File Origin
USVendor Threat Intelligence
Result
Behaviour
Result
Behaviour
Malware Config
Unpacked files
8db0cd1d0244de2a22f748c4d8fdac91f6850f1fef19bc7f2afe1d5cefb5b228
bb217671489213dfb4eefff0d0af47621615d9a0c85415c0e31f2cb08786d359
8f20020d5b0669c889435750b00452672cb17fc2a87225a5341040bc05afc008
f87d454dd49c3b0c8bd81219f17b67c51056bfb45b6e60dc6eb9d9d5cbfb2594
e77e98d44648b068a2036f4eb4ce0d528d0ae2172f3c375294fc56a6e219b771
c78ba64e698b6db6a9a1c05b3c82c5d12ba12d668a440f844f287828c031d825
65ef4c948050199ef320f05d1a5144f5e1f188d824e01e6f50f58cea83f56dd9
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.