8555743631267a78de02ae65d5454e3bfc2ac6c5336dab259fcff5316aba840c
Classification: Malicious
8555743631267a78de02ae65d5454e3bfc2ac6c5336dab259fcff5316aba840c is a malicious file sample. Linked to Quasarrat malware. Detected by 55 antivirus engines.
Detection summary
- 55 antivirus detections (79% detection ratio)
- 0 IDS alerts
- 4 processes observed
- 2 contacted hosts
- 1 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-01-08 18:30:05 |
2026-09-02 22:45:04 |
malicious-activity
|
|
| QuasarRAT |
MalwareBazaar Abuse.ch |
2024-01-08 11:55:42 |
2024-01-08 11:55:42 |
malicious-activity
|
S0262 QuasarRAT
|
Tags
evasive
infostealer
njrat
malicious
Sample information
- Filenames
- 8555743631267a78de02ae65d5454e3bfc2ac6c5336dab259fcff5316aba840c, 85557.Backdoor.exe, Client.exe
- File type
- application/x-dosexec
- Size
- 3266048 bytes
- MD5
6f293272df899a043acbf788caf81c1c
- SHA-1
b560917bf5c67c37eb646acc9880c5a80620fce5
- SHA-256
8555743631267a78de02ae65d5454e3bfc2ac6c5336dab259fcff5316aba840c
- First indexed
- 2024-01-08 13:19:08
- Last updated
- 2026-09-02 22:45:04
Antivirus detections
| Engine | Detection |
| Bkav | W32.AIDetectMalware.CS |
| Lionic | Trojan.Win32.Quasar.4!c |
| MicroWorld-eScan | Generic.MSIL.PasswordStealerA.EBDBFD62 |
| ClamAV | Win.Malware.Generic-9883083-0 |
| CAT-QuickHeal | Trojan.Generic.TRFH927 |
| Skyhigh | BehavesLike.Win32.Generic.wh |
| McAfee | GenericRXLX-DS!6F293272DF89 |
| Malwarebytes | Generic.Malware.AI.DDS |
| Sangfor | Trojan.Win32.Save.a |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Alibaba | Backdoor:MSIL/Quasar.5ad64950 |
| K7GW | Trojan ( 005690671 ) |
| K7AntiVirus | Trojan ( 005690671 ) |
| BitDefenderTheta | Gen:NN.ZemsilF.36680.hp0@ai4zD4j |
| VirIT | Trojan.Win32.MSIL.MJ |
| Symantec | ML.Attribute.HighConfidence |
| Elastic | malicious (high confidence) |
| ESET-NOD32 | a variant of MSIL/Agent.CLQ |
| APEX | Malicious |
| Cynet | Malicious (score: 100) |
| Kaspersky | HEUR:Trojan.MSIL.Quasar.gen |
| BitDefender | Generic.MSIL.PasswordStealerA.EBDBFD62 |
| NANO-Antivirus | Trojan.Win32.Quasar.kgpsvm |
| Avast | MSIL:Quasar-A [Rat] |
| Tencent | Trojan.MSIL.Quasar.ka |
| Emsisoft | Trojan.Agent (A) |
| F-Secure | Heuristic.HEUR/AGEN.1365341 |
| DrWeb | BackDoor.QuasarNET.3 |
| VIPRE | Generic.MSIL.PasswordStealerA.EBDBFD62 |
| TrendMicro | Backdoor.Win32.QUASARRAT.YXEAFZ |
| Sophos | Troj/Quasar-AF |
| SentinelOne | Static AI - Malicious PE |
| Webroot | W32.Trojan.Quasar |
| Google | Detected |
| Avira | HEUR/AGEN.1365341 |
| Antiy-AVL | Trojan/MSIL.Quasar |
| Kingsoft | malware.kb.c.926 |
| Microsoft | Backdoor:MSIL/Quasar!atmn |
| Gridinsoft | Spy.Win32.Keylogger.dd!n |
| Arcabit | Generic.MSIL.PasswordStealerA.EBDBFD62 |
| ZoneAlarm | HEUR:Trojan.MSIL.Quasar.gen |
| GData | MSIL.Backdoor.Quasar.A |
| Varist | W32/MSIL_Troj.BTX.gen!Eldorado |
| AhnLab-V3 | Backdoor/Win32.QuasarRAT.R341693 |
| VBA32 | Trojan.MSIL.Quasar.Heur |
| MAX | malware (ai score=89) |
| Cylance | unsafe |
| Panda | Trj/Chgt.AD |
| TrendMicro-HouseCall | Backdoor.Win32.QUASARRAT.YXEAFZ |
| Rising | Backdoor.Quasar!1.E5F1 (CLASSIC) |
| Yandex | Trojan.Agent!6x0OZVeqZjs |
| Ikarus | Trojan-Spy.Agent |
| Fortinet | MSIL/Agent.BPH!tr |
| AVG | MSIL:Quasar-A [Rat] |
| DeepInstinct | MALICIOUS |
Process list
| Name | Command line |
| 85557.Backdoor.exe | |
| schtasks.exe | "schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "%APPDATA%\SubDir\Client.exe" /rl HIGHEST /f |
| Client.exe | |
| schtasks.exe | "schtasks" /create /tn "Quasar Client Startup" /sc ONLOGON /tr "%APPDATA%\SubDir\Client.exe" /rl HIGHEST /f |