🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ff4e059d3f8c4285958c7dcddb1ce9084ea490e8269c514fbc2d3a1403914c9c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



QuasarRAT


Vendor detections: 16


Intelligence 16 IOCs YARA 4 File information Comments

SHA256 hash: ff4e059d3f8c4285958c7dcddb1ce9084ea490e8269c514fbc2d3a1403914c9c
SHA3-384 hash: b3a80cd83f008df13650951cf83414f53ab3e1d19e542ae8cd98f0a37e3a2a993eebcfda939ec69c61b9322003604c4c
SHA1 hash: 9a8c27798f6b5b0f9b672ed569aa028cbbc45467
MD5 hash: 931a60569590d37c6df6fafc7e8a93cf
humanhash: high-mobile-early-yellow
File name:file
Download: download sample
Signature QuasarRAT
File size:251'392 bytes
First seen:2026-09-26 01:44:30 UTC
Last seen:2026-09-26 01:50:00 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'245 x AgentTesla, 20'500 x Formbook, 12'374 x SnakeKeylogger)
ssdeep 6144:m26+X70DfPJxIezeTPz6R+TJqGVDJf6AgJH6ImjGlNbaYpU:7972QeaOR+lq2EjZAjwNbF
TLSH T17A342304CBDEE65AE56006318DD781CB012CBA37FE77D50D6920B1CB6F6192DC7892BA
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter Bitsight
Tags:d52f85 dropped-by-amadey exe QuasarRAT


Avatar
Bitsight
url: http://62.60.226.140/files/6332047396/wh0Vgsw.exe

Intelligence


File Origin
# of uploads :
3
# of downloads :
195
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-09-26 01:51:26 UTC
Tags:
quasar

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Launching a process
Creating a file in the %temp% directory
Deleting a recently created file
Connecting to a non-recommended domain
Connection attempt
Enabling autorun by creating a file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
base64 packed
Verdict:
inconclusive
YARA:
11 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.00 Win 32 Exe x86
Threat name:
ByteCode-MSIL.Trojan.Zilla
Status:
Malicious
First seen:
2026-09-26 01:45:34 UTC
File Type:
PE (.Net Exe)
Extracted files:
1
AV detection:
21 of 36 (58.33%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:quasar botnet:test discovery execution persistence spyware trojan
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Reads the TCP/IP host and domain name from the registry
Family: Quasar RAT
Quasar payload
Malware Config
C2 Extraction:
194.26.192.168:9110
Unpacked files
SH256 hash:
ff4e059d3f8c4285958c7dcddb1ce9084ea490e8269c514fbc2d3a1403914c9c
MD5 hash:
931a60569590d37c6df6fafc7e8a93cf
SHA1 hash:
9a8c27798f6b5b0f9b672ed569aa028cbbc45467
SH256 hash:
d579633606183a720483eb20f1e1cf14cbb9375bcba10182a772d51ff6d3ceff
MD5 hash:
229ae5e1c7042c7632cdb8a6bb9c7753
SHA1 hash:
56191d142a3e2d80f8c08535cf87337bf8dcb887
Detections:
QuasarRAT cn_utf8_windows_terminal INDICATOR_SUSPICIOUS_Binary_References_Browsers INDICATOR_SUSPICIOUS_EXE_NoneWindowsUA INDICATOR_SUSPICIOUS_GENInfoStealer MAL_QuasarRAT_May19_1 malware_windows_xrat_quasarrat MALWARE_Win_QuasarStealer Vermin_Keylogger_Jan18_1
Malware family:
QuasarRAT
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:WIN_Sample_Unique_69354b41
Author:Marjoriefort
Description:Specimen unique (soumission Bazaar) - strings distinctifs propres au sample
Reference:69354b41e10daf03d3f3af881b32d5c0fec56b1cfe96629fd4c5263413a42854.exe

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

QuasarRAT

Executable exe ff4e059d3f8c4285958c7dcddb1ce9084ea490e8269c514fbc2d3a1403914c9c

(this sample)

  
Dropped by
Amadey
  
Delivery method
Distributed via web download

Comments