MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 dfd7432d2e19067b096ccbb0aaab030bfb4dbc78f5cf6b6b5971e5f6871f7204. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
QuasarRAT
Vendor detections: 8
| SHA256 hash: | dfd7432d2e19067b096ccbb0aaab030bfb4dbc78f5cf6b6b5971e5f6871f7204 |
|---|---|
| SHA3-384 hash: | 4f097875adb5bde8bca8a37cbf27171eab980b41338769b1c0a1f6262027c36a8d8df39a5874fb49d6d7e41f1a51a1b7 |
| SHA1 hash: | 8090b1762283891671a2a549f4f54edb23e53a8f |
| MD5 hash: | fa8fdc6064f86f29fe4f8e4c1352f4ed |
| humanhash: | connecticut-blossom-fix-stream |
| File name: | decoded_injected_shellcode.rar |
| Download: | download sample |
| Signature | QuasarRAT |
| File size: | 1'295'106 bytes |
| First seen: | 2026-02-09 15:32:19 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 24576:sXWFw9XDEp4atwWQnkylLjp887E3PEta5qpkS1Ige9D+ri:sX2qTEpwyyhTwfEKjS1Te9D+e |
| TLSH | T1F05533A07DFC6429FDD8194FE6BD234F97840E810F61FAAA899561F497072B32981F34 |
| TrID | 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1) 38.4% (.RAR) RAR compressed archive (gen) (5000/1) |
| Magika | rar |
| Reporter | |
| Tags: | 193-161-193-99 QuasarRAT rar |
Intelligence
File Origin
# of uploads :
1
# of downloads :
66
Origin country :
ITFile Archive Information
This file archive contains 1 file(s), sorted by their relevance:
| File name: | decoded_injected_shellcode.bin |
|---|---|
| File size: | 1'302'053 bytes |
| SHA256 hash: | 76114812ca9a8d15ce6e60df57036feee4dd8311ea9d012669206f341d58ba75 |
| MD5 hash: | 09d67b7119deab290876383eeb497200 |
| MIME type: | application/octet-stream |
| Signature | QuasarRAT |
Vendor Threat Intelligence
Verdict:
Malicious
Score:
70%
Tags:
malware
Verdict:
Likely Malicious
Threat level:
7.5/10
Confidence:
100%
Tags:
donut
Verdict:
Malicious
File Type:
rar
First seen:
2026-02-09T15:12:00Z UTC
Last seen:
2026-02-09T15:23:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
Rar Archive
Threat name:
Win64.Trojan.Donut
Status:
Malicious
First seen:
2026-02-09 15:33:29 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
9 of 24 (37.50%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
donutloader
Score:
10/10
Tags:
family:donutloader loader
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
QuasarRAT
rar dfd7432d2e19067b096ccbb0aaab030bfb4dbc78f5cf6b6b5971e5f6871f7204
(this sample)
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.