MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dfd7432d2e19067b096ccbb0aaab030bfb4dbc78f5cf6b6b5971e5f6871f7204. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



QuasarRAT


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: dfd7432d2e19067b096ccbb0aaab030bfb4dbc78f5cf6b6b5971e5f6871f7204
SHA3-384 hash: 4f097875adb5bde8bca8a37cbf27171eab980b41338769b1c0a1f6262027c36a8d8df39a5874fb49d6d7e41f1a51a1b7
SHA1 hash: 8090b1762283891671a2a549f4f54edb23e53a8f
MD5 hash: fa8fdc6064f86f29fe4f8e4c1352f4ed
humanhash: connecticut-blossom-fix-stream
File name:decoded_injected_shellcode.rar
Download: download sample
Signature QuasarRAT
File size:1'295'106 bytes
First seen:2026-02-09 15:32:19 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:sXWFw9XDEp4atwWQnkylLjp887E3PEta5qpkS1Ige9D+ri:sX2qTEpwyyhTwfEKjS1Te9D+e
TLSH T1F05533A07DFC6429FDD8194FE6BD234F97840E810F61FAAA899561F497072B32981F34
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter ShadowOpCode
Tags:193-161-193-99 QuasarRAT rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:decoded_injected_shellcode.bin
File size:1'302'053 bytes
SHA256 hash: 76114812ca9a8d15ce6e60df57036feee4dd8311ea9d012669206f341d58ba75
MD5 hash: 09d67b7119deab290876383eeb497200
MIME type:application/octet-stream
Signature QuasarRAT
Vendor Threat Intelligence
Verdict:
Malicious
Score:
70%
Tags:
malware
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
donut
Verdict:
Malicious
File Type:
rar
First seen:
2026-02-09T15:12:00Z UTC
Last seen:
2026-02-09T15:23:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
Rar Archive
Threat name:
Win64.Trojan.Donut
Status:
Malicious
First seen:
2026-02-09 15:33:29 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
donutloader
Score:
  10/10
Tags:
family:donutloader loader
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

QuasarRAT

rar dfd7432d2e19067b096ccbb0aaab030bfb4dbc78f5cf6b6b5971e5f6871f7204

(this sample)

Comments