🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dea330aa363de864d6f56d750fc1185e778971227abcfb0be0557cef78bf0c7c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



N-W0rm


Vendor detections: 21


Intelligence 21 IOCs 1 YARA 27 File information Comments

SHA256 hash: dea330aa363de864d6f56d750fc1185e778971227abcfb0be0557cef78bf0c7c
SHA3-384 hash: ab53dc3de1e425c7932ccf8801a8d2ebda77cce3835091063a7404dedff72d6f21083a798c6183319314a323b56132be
SHA1 hash: 1c7b07ce26e66c1a66f6c272ce6eb04c292d3801
MD5 hash: f20613bf3ee0b8561192ceb16e2a655b
humanhash: hydrogen-princess-nine-monkey
File name:dea330aa363de864d6f56d750fc1185e778971227abcf.exe
Download: download sample
Signature N-W0rm
File size:14'737'920 bytes
First seen:2026-01-14 09:55:09 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'239 x AgentTesla, 20'490 x Formbook, 12'372 x SnakeKeylogger)
ssdeep 393216:dEfEy2tyv2kOsdZLfjS+j/EpVfE24reOtQDBS:SfEyjOslrJelE29OC
TLSH T157E612023BE88ABBC59E0775D4F206A603F2F5412763DB5F1A80AB6D2D83B915D117E3
TrID 41.0% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
23.3% (.EXE) Win32 EXE PECompact compressed (generic) (41569/9/9)
9.2% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
5.9% (.EXE) Win64 Executable (generic) (10522/11/4)
5.6% (.EXE) DOS Borland compiled Executable (generic) (10000/1/2)
Magika pebin
Reporter abuse_ch
Tags:exe N-W0rm


Avatar
abuse_ch
N-W0rm C2:
104.223.8.71:5782

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
104.223.8.71:5782 https://threatfox.abuse.ch/ioc/1732176/

Intelligence


File Origin
# of uploads :
1
# of downloads :
139
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
dea330aa363de864d6f56d750fc1185e778971227abcfb0be0557cef78bf0c7c.exe
Verdict:
Suspicious activity
Analysis date:
2026-01-14 09:37:37 UTC
Tags:
evasion amsi-bypass

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
quasar emotet spam
Verdict:
Malicious
File Type:
exe x32
First seen:
2025-12-27T04:48:00Z UTC
Last seen:
2026-01-15T06:18:00Z UTC
Hits:
~100
Detections:
Trojan.MSIL.Quasar.b Trojan-Spy.MSIL.Downeks.sb Trojan-PSW.MSIL.Virinom.sb Trojan.Win32.Quasar.sb Trojan.MSIL.Quasar.sb HEUR:Trojan.Win32.Generic HEUR:Trojan.MSIL.R77.gen HEUR:Trojan.MSIL.Quasar.gen Trojan-Spy.Quasar.HTTP.ServerRequest Trojan-PSW.Win32.Stealer.sb Trojan.MSIL.Quasar.a HEUR:Trojan-Spy.MSIL.Agent.sb HEUR:Backdoor.MSIL.Quasar.gen
Result
Threat name:
Quasar, XRat
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
.NET source code contains process injector
.NET source code references suspicious native API functions
Antivirus / Scanner detection for submitted sample
Disables UAC (registry)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Uses known network protocols on non-standard ports
Yara detected Quasar RAT
Yara detected XRat
Behaviour
Behavior Graph:
Verdict:
QuasarRat
YARA:
14 match(es)
Tags:
.Net Executable Malicious Managed .NET PDB Path PE (Portable Executable) PE File Layout QuasarRat RAT SOS: 0.24 SOS: 0.27 SOS: 0.31 SOS: 0.32 Win 32 Exe x86
Threat name:
ByteCode-MSIL.Backdoor.Quasar
Status:
Malicious
First seen:
2026-01-14 09:37:38 UTC
File Type:
PE (.Net Exe)
Extracted files:
54
AV detection:
23 of 36 (63.89%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
r77rootkit quasarrat
Similar samples:
Result
Malware family:
Score:
  10/10
Tags:
family:quasar defense_evasion discovery spyware trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
System policy modification
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Checks whether UAC is enabled
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Downloads MZ/PE file
Quasar RAT
Quasar family
Quasar payload
UAC bypass
Verdict:
Malicious
Tags:
rootkit rat quasar_rat Win.Packed.QuasarRAT-10012744-0 External_IP_Lookup IP_address_lookup_website
YARA:
Windows_Rootkit_R77_ee853c9f JPCERTCC_Quasar MALWARE_Win_QuasarRAT Quasar_RAT_1 Windows_Trojan_Quasarrat_e52df647 malware_Quasar_strings malware_windows_quasarrat
Unpacked files
SH256 hash:
dea330aa363de864d6f56d750fc1185e778971227abcfb0be0557cef78bf0c7c
MD5 hash:
f20613bf3ee0b8561192ceb16e2a655b
SHA1 hash:
1c7b07ce26e66c1a66f6c272ce6eb04c292d3801
Detections:
QuasarRAT
SH256 hash:
e137863a79da797f08e7a137280ff2a123809044a888fd75ce9c973198915abe
MD5 hash:
0f0b50d92e030b8965ce669c8058fa6e
SHA1 hash:
257b3f0402285a29f4618b32958c208b3e9d4c4d
SH256 hash:
2d5e418aac76968d8aa792b847bf72b8ab3b5b0beebf8d9fd169328f95decbe1
MD5 hash:
11e2ddee4e43ed149811b18a165f5eb8
SHA1 hash:
06d9e144cf5d3f3f96ce02c8983b869d293cb399
SH256 hash:
ba219ef5c872b99f95467396722ffc8e5236dfb1230f68e93917cb0e24b09441
MD5 hash:
2ae720c59177a29b5b26d66bbafad219
SHA1 hash:
151f6b1b3b67a59cc924537a14ff6bfe27ed0ec0
SH256 hash:
9e1def27b804df9ba97fd07f9de835c70660ae568c00950102f70034e293a684
MD5 hash:
f90b05d294f094a122c6b99b5a820cb8
SHA1 hash:
757803f0e58269ac37ff81489465f80108032636
SH256 hash:
586aad71e68c749b050b650b54c8b6783a17812f7572354fd11a3d56e34b5758
MD5 hash:
348c85ac40d307858026f09b8ff063c3
SHA1 hash:
f51654a0398711ee5be2d8e456cd35fabaab34b8
SH256 hash:
52ed2afc42270495e2263d999304afbf6f8e5e57f366c1d586d994f80c7f9f8c
MD5 hash:
ff8794f3387ebfad0d6304a6f60d1cd0
SHA1 hash:
70f0e834ca81c93dd7f97eb861414c5e26c64cf2
SH256 hash:
6d69c2edcf13d4c8754d5bcdaf23e27239ca80e0b87773babb05e6eefb8621f5
MD5 hash:
70f7c9e2f0c6659c42c91e76d9141747
SHA1 hash:
3d1110a84e53fb564a3e0aae51037622116fe32c
SH256 hash:
04cbf10077320c0e64f61c4ec5f4fdd297d8e6f538233ddc24c99e8e603c24ce
MD5 hash:
2fb4e4ed96035fe21ffa2670c73828da
SHA1 hash:
6282521b8ae8057b02764959e408ee23e5923cc7
SH256 hash:
c23e460daced2851671282a4d93672f0fdf48e20947f6cd3617df490f24d459c
MD5 hash:
e56aababacd1c005011ba51d2c349370
SHA1 hash:
341d9c3344e0c801636ba956d4796edd2b539ce7
SH256 hash:
42166c84a841de454a8e5ed8ef6dc21c680dbcaac9f07a4f7f951d1acecc840d
MD5 hash:
de6b38f6a612ca47d06eb3bf64c824e0
SHA1 hash:
ac19d99dc3b36ed57068b3d2bdd97990bbe13a6f
Malware family:
QuasarRAT
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Borland
Author:malware-lu
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:INDICATOR_SUSPICIOUS_EXE_NoneWindowsUA
Author:ditekSHen
Description:Detects Windows executables referencing non-Windows User-Agents
Rule name:INDICATOR_SUSPICIOUS_GENInfoStealer
Author:ditekSHen
Description:Detects executables containing common artifacts observed in infostealers
Rule name:Lumma_Stealer_Detection
Author:ashizZz
Description:Detects a specific Lumma Stealer malware sample using unique strings and behaviors
Reference:https://seanthegeek.net/posts/compromized-store-spread-lumma-stealer-using-fake-captcha/
Rule name:malware_Quasar_strings
Author:JPCERT/CC Incident Response Group
Description:detect QuasarRAT in memory
Rule name:MALWARE_Win_QuasarRAT
Author:ditekSHen
Description:QuasarRAT payload
Rule name:Multifamily_RAT_Detection
Author:Lucas Acha (http://www.lukeacha.com)
Description:Generic Detection for multiple RAT families, PUPs, Packers and suspicious executables
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Quasar
Author:JPCERT/CC Incident Response Group
Description:detect QuasarRAT in memory
Rule name:quasarrat
Author:jeFF0Falltrades
Rule name:QuasarRAT
Author:ditekshen
Description:QuasarRAT payload
Rule name:Quasar_RAT_1
Author:Florian Roth (Nextron Systems)
Description:Detects Quasar RAT
Reference:https://www.pwc.co.uk/cyber-security/pdf/cloud-hopper-annex-b-final.pdf
Rule name:Quasar_RAT_1
Author:@SOCRadar
Description:Detects Quasar RAT
Rule name:Quasar_RAT_1_RID2B54
Author:Florian Roth
Description:Detects Quasar RAT
Reference:https://www.pwc.co.uk/cyber-security/pdf/cloud-hopper-annex-b-final.pdf
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_All_Windows_PE_Malware
Author:DiegoAnalytics
Description:Detects Windows PE malware of all types, avoids non-executables like .html
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:Windows_Rootkit_R77_ee853c9f
Author:Elastic Security
Reference:https://www.elastic.co/security-labs/elastic-security-labs-steps-through-the-r77-rootkit
Rule name:Windows_Trojan_Quasarrat_e52df647
Author:Elastic Security

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments