🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c36db5c9e90ed0abac94523ba9f0316e5dc662b9f331d548be9b8ea80806c9ab. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



QuasarRAT


Vendor detections: 14


Intelligence 14 IOCs 1 YARA 4 File information Comments

SHA256 hash: c36db5c9e90ed0abac94523ba9f0316e5dc662b9f331d548be9b8ea80806c9ab
SHA3-384 hash: 72fad503dd2f73c5df1ff4265d408f80099d2c51123e5a555e52ae4b1b38ef15ca116b0035ede7ea19f08acec4b72a85
SHA1 hash: f88904be90dfa1b35ca8f46350484023ead80157
MD5 hash: 25b916160015a5e532172b39e6b54bda
humanhash: foxtrot-grey-carbon-kansas
File name:WalletAiFinder_Crypter.bat
Download: download sample
Signature QuasarRAT
File size:14'211'111 bytes
First seen:2025-12-18 17:32:08 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/plain
ssdeep 49152:JbaMWdgfEYH0Th+EM6R+gu1DFJ0Di410auHlCtJ+1biL6gGOHohdS1XzOdnLoyGJ:M
TLSH T170E601B74E64B967C3AF0914A9BF190C0FFE8889C0017B59A3E1DE79A17672515FB203
Magika batch
Reporter smica83
Tags:bat QuasarRAT

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
23.160.168.167:4782 https://threatfox.abuse.ch/ioc/1663007/

Intelligence


File Origin
# of uploads :
1
# of downloads :
137
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Malware family:
ID:
1
File name:
WalletAiFinder_Crypter.bat
Verdict:
Malicious activity
Analysis date:
2025-12-18 17:34:13 UTC
Tags:
auto-sch rat quasar remote auto-reg uac auto-startup xworm evasion susp-powershell

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.1%
Tags:
asyncrat autorun quasar
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Creating a process from a recently created file
Creating a window
Running batch commands
Creating a process with a hidden window
Launching a process
Creating a file
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-18T04:50:00Z UTC
Last seen:
2025-12-18T14:56:00Z UTC
Hits:
~10
Detections:
PDM:Trojan.Win32.Generic HEUR:Trojan.BAT.Alien.gen Backdoor.Agent.TCP.C&C not-a-virus:PDM:Adware.Win32.NotB.aa
Result
Threat name:
Quasar, XRat, XWorm
Detection:
malicious
Classification:
troj.adwa.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
.NET source code contains very large strings
Adds a directory exclusion to Windows Defender
Antivirus detection for dropped file
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Command shell drops VBS files
Creates a thread in another existing process (thread injection)
Found large BAT file
Found malware configuration
Found suspicious powershell code related to unpacking or dynamic code loading
Hides that the sample has been downloaded from the Internet (zone.identifier)
Hooks files or directories query functions (used to hide files and directories)
Hooks processes query functions (used to hide processes)
Hooks registry keys query functions (used to hide registry keys)
Injects code into the Windows Explorer (explorer.exe)
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Modifies the context of a thread in another process (thread injection)
Modifies the hosts file
Modifies the prolog of user mode functions (user mode inline hooks)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Mutes Antivirus updates and installments via hosts file black listing
Powershell drops PE file
Protects its processes via BreakOnTermination flag
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Sets debug register (to hijack the execution of another thread)
Sigma detected: Base64 Encoded PowerShell Command Detected
Sigma detected: Malicious Base64 Encoded PowerShell Keywords in Command Lines
Sigma detected: PowerShell Base64 Encoded FromBase64String Cmdlet
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious PowerShell Parameter Substring
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious powershell command line found
Unusual module load detection (module proxying)
Uses ipconfig to lookup or modify the Windows network settings
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Yara detected Obfuscated Powershell
Yara detected Powershell decode and execute
Yara detected Quasar RAT
Yara detected XRat
Yara detected XWorm
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1835848 Sample: WalletAiFinder_Crypter.bat Startdate: 18/12/2025 Architecture: WINDOWS Score: 100 117 www.msftncsi.com.edgesuite.net 2->117 119 www.msftncsi.com 2->119 121 4 other IPs or domains 2->121 153 Suricata IDS alerts for network traffic 2->153 155 Found malware configuration 2->155 157 Malicious sample detected (through community Yara rule) 2->157 159 25 other signatures 2->159 14 cmd.exe 2 2->14         started        18 Sirdur.exe 2->18         started        20 SeroXen.exe 2->20         started        22 SeroXen.exe 2->22         started        signatures3 process4 file5 107 C:\Users\user\AppData\...\run_hidden.vbs, ASCII 14->107 dropped 189 Suspicious powershell command line found 14->189 191 Command shell drops VBS files 14->191 193 Bypasses PowerShell execution policy 14->193 24 cscript.exe 2 14->24         started        26 conhost.exe 14->26         started        195 Antivirus detection for dropped file 18->195 197 Multi AV Scanner detection for dropped file 18->197 signatures6 process7 process8 28 cmd.exe 3 24->28         started        signatures9 185 Suspicious powershell command line found 28->185 187 Command shell drops VBS files 28->187 31 WalletAiFinder.exe 5 28->31         started        35 powershell.exe 8 28->35         started        37 conhost.exe 28->37         started        39 16 other processes 28->39 process10 file11 109 C:\Users\user\AppData\...\WalletFinder.exe, PE32 31->109 dropped 111 C:\Users\user\AppData\Roaming\Update.exe, PE32 31->111 dropped 113 C:\Users\user\AppData\Roaming\SeroXen.exe, PE32 31->113 dropped 135 Antivirus detection for dropped file 31->135 137 Multi AV Scanner detection for dropped file 31->137 41 SeroXen.exe 14 7 31->41         started        46 WalletFinder.exe 4 31->46         started        48 Update.exe 31->48         started        115 C:\Users\user\AppData\...\WalletAiFinder.exe, PE32 35->115 dropped 139 Found suspicious powershell code related to unpacking or dynamic code loading 35->139 141 Powershell drops PE file 35->141 signatures12 process13 dnsIp14 125 ip-api.com 208.95.112.1, 49693, 49698, 80 TUT-ASUS United States 41->125 97 C:\Users\user\AppData\Roaming\...\Client.exe, PE32 41->97 dropped 99 C:\Windows\System32\drivers\etc\hosts, ASCII 41->99 dropped 171 Antivirus detection for dropped file 41->171 173 Multi AV Scanner detection for dropped file 41->173 175 Suspicious powershell command line found 41->175 183 5 other signatures 41->183 50 Client.exe 41->50         started        53 powershell.exe 41->53         started        55 schtasks.exe 41->55         started        64 2 other processes 41->64 101 C:\Users\user\AppData\...\SeedBrutoforce.exe, PE32 46->101 dropped 103 C:\Users\user\AppData\Roaming\dont del.bat, ASCII 46->103 dropped 57 cmd.exe 46->57         started        59 SeedBrutoforce.exe 46->59         started        127 23.160.168.167, 1111, 2212, 4782 HOSTCRAMHostCramLLCUS Reserved 48->127 105 C:\Users\user\AppData\Local\Sirdur.exe, PE32 48->105 dropped 177 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 48->177 179 Protects its processes via BreakOnTermination flag 48->179 181 Uses schtasks.exe or at.exe to add and modify task schedules 48->181 62 schtasks.exe 48->62         started        file15 signatures16 process17 dnsIp18 143 Antivirus detection for dropped file 50->143 145 Multi AV Scanner detection for dropped file 50->145 147 Hides that the sample has been downloaded from the Internet (zone.identifier) 50->147 66 schtasks.exe 50->66         started        149 Loading BitLocker PowerShell Module 53->149 68 conhost.exe 53->68         started        70 conhost.exe 55->70         started        151 Suspicious powershell command line found 57->151 72 powershell.exe 57->72         started        76 conhost.exe 57->76         started        129 23.49.5.132, 49738, 49742, 49743 AKAMAI-ASUS United States 59->129 131 23.49.5.148, 49694, 49740, 49741 AKAMAI-ASUS United States 59->131 133 3 other IPs or domains 59->133 78 conhost.exe 62->78         started        80 conhost.exe 64->80         started        82 conhost.exe 64->82         started        signatures19 process20 dnsIp21 84 conhost.exe 66->84         started        123 ipwho.is 15.204.213.5, 443, 49736 HP-INTERNET-ASUS United States 72->123 163 Injects code into the Windows Explorer (explorer.exe) 72->163 165 Sets debug register (to hijack the execution of another thread) 72->165 167 Writes to foreign memory regions 72->167 169 3 other signatures 72->169 86 explorer.exe 72->86 injected 89 svchost.exe 72->89 injected 91 svchost.exe 72->91 injected 93 2 other processes 72->93 signatures22 process23 signatures24 161 Unusual module load detection (module proxying) 86->161 95 Sirdur.exe 86->95         started        process25
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-12-18 07:40:36 UTC
File Type:
Text
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:donutloader family:quasar family:xworm botnet:office04 defense_evasion discovery execution loader persistence rat spyware trojan
Behaviour
Uses Task Scheduler COM API
Suspicious use of WriteProcessMemory
Suspicious use of UnmapMainImage
Suspicious use of SendNotifyMessage
Suspicious use of FindShellTrayWindow
Suspicious use of AdjustPrivilegeToken
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: EnumeratesProcesses
Scheduled Task/Job: Scheduled Task
Modifies registry class
Modifies data under HKEY_USERS
Gathers network information
Delays execution with timeout.exe
System Location Discovery: System Language Discovery
Enumerates physical storage devices
Drops file in System32 directory
Adds Run key to start application
Looks up external IP address via web service
Indicator Removal: Clear Windows Event Logs
Executes dropped EXE
Drops startup file
Checks computer location settings
Drops file in Drivers directory
Command and Scripting Interpreter: PowerShell
Badlisted process makes network request
Xworm family
Xworm
Quasar payload
Quasar family
Quasar RAT
Donutloader family
DonutLoader
Detects DonutLoader
Detect Xworm Payload
Malware Config
C2 Extraction:
23.160.168.167:2212
23.160.168.167:1111
23.160.168.167:4782
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:SUSP_PowerShell_Caret_Obfuscation_2
Author:Florian Roth (Nextron Systems)
Description:Detects powershell keyword obfuscated with carets
Reference:Internal Research
Rule name:SUSP_PowerShell_Caret_Obfuscation_2_RID347B
Author:Florian Roth
Description:Detects powershell keyword obfuscated with carets
Reference:Internal Research
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments