s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-539f53d61ace3821e6b78f54600e7ee6b87b170de9d96ece7c152328ff0959d6 high

📛 Threat Title

QuasarRAT: cliphot69.exe

Category: QuasarRAT Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 3638272 bytes. Tags: exe, QUASARRAT, rat. Reporter: cleanabuseweb. First seen: 2026-05-15 11:37:08.

Indicators of Compromise (5)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain cliphot69.exe VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/cliphot69.exe

IOC database

Type
domain
Value
cliphot69.exe
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat MB-539f53d61ace3821e6b78f54600e7ee6b87b170de9d96ece7c152328ff0959d6

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/cliphot69.exe

hash_imphash f34d5f2d4577ed6d9ceec516c1f5a744

IOC database

Type
hash_imphash
Value
f34d5f2d4577ed6d9ceec516c1f5a744
First seen
Last seen
Attached to this threat
Appears in
656 threats
Description
imphash of URLhaus payload 61d424c2e3c5d8db…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 539f53d61ace3821e6b78f54600e7ee6b87b170de9d96ece7c152328ff0959d6 VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/539f53d61ace3821e6b78f54600e7ee6b87b170de9d96ece7c152328ff0959d6
1 feed

IOC database

Type
hash_sha256
Value
539f53d61ace3821e6b78f54600e7ee6b87b170de9d96ece7c152328ff0959d6
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
QuasarRAT

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/539f53d61ace3821e6b78f54600e7ee6b87b170de9d96ece7c152328ff0959d6

hash_sha1 5cd05132c8f5487bd9869c976358fc321a7b20fc VT 56 / 73 1 feed

IOC database

Type
hash_sha1
Value
5cd05132c8f5487bd9869c976358fc321a7b20fc
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 56 of 73 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Backdoor/Win32.QuasarRAT.R341693
Alibaba malicious Backdoor:MSIL/Quasar.43a06d54
alibabacloud malicious Backdoor:MSIL/Quasar.server
ALYac malicious Gen:Variant.Application.fca.3927
Antiy-AVL malicious Trojan/MSIL.Quasar
APEX malicious Malicious
Arcabit malicious Trojan.Application.fca.DF57
Avast malicious MSIL:Quasar-A [Rat]
AVG malicious MSIL:Quasar-A [Rat]
Avira malicious TR/Quasar.A
BitDefender malicious Gen:Variant.Application.fca.3927
Bkav malicious W32.Malware.152EB275
ClamAV malicious Win.Malware.Generic-9883083-0
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.trojan.quasar
Cylance malicious Unsafe
DeepInstinct malicious MALICIOUS
DrWeb malicious BackDoor.Quasar.299
Elastic malicious Windows.Generic.Threat
Emsisoft malicious Gen:Variant.Application.fca.3927 (B)
ESET-NOD32 malicious MSIL/Agent.CLQ trojan
F-Secure malicious Trojan.TR/Quasar.A
Fortinet malicious MSIL/Agent.BPH!tr
GData malicious MSIL.Backdoor.Quasar.A
Google malicious Detected
huorong malicious Trojan/MSIL.Obfuscated.g!crit
Jiangmin malicious Trojan.MSIL.aogzw
K7AntiVirus malicious Trojan ( 005b1c021 )
K7GW malicious Trojan ( 005b1c021 )
Kaspersky malicious HEUR:Trojan.MSIL.Quasar.gen
Kingsoft malicious MSIL.Trojan.Quasar.gen
Lionic malicious Trojan.Win32.Quasar.4!c
Malwarebytes malicious Generic.Trojan.Agent.DDS
MaxSecure malicious Trojan.Malware.300983.susgen
McAfeeD malicious Trojan:Win/QuasarRAT.AA
Microsoft malicious Backdoor:MSIL/Quasar!atmn
MicroWorld-eScan malicious Gen:Variant.Application.fca.3927
NANO-Antivirus malicious Trojan.Win32.Quasar.lelzaq
Paloalto malicious generic.ml
Panda malicious Trj/CI.A
Rising malicious Backdoor.Quasar!1.E5F1 (CLASSIC)
Sangfor malicious Suspicious.Win32.Save.a
SentinelOne malicious Static AI - Malicious PE
Skyhigh malicious Quasar!C4980A5B654F
Sophos malicious Troj/Quasar-AF
Symantec malicious ML.Attribute.HighConfidence
TrellixENS malicious GenericRXLX-DS!C4980A5B654F
TrendMicro malicious Backdoor.Win32.QUASARRAT.YXGEOZ
TrendMicro-HouseCall malicious Trojan.Win32.VSX.PE04CA3
Varist malicious W32/MSIL_Troj.BTX.gen!Eldorado
VBA32 malicious Trojan.MSIL.Quasar.Heur
VIPRE malicious Gen:Variant.Application.fca.3927
VirIT malicious Trojan.Win32.MSIL_Heur.B
ViRobot malicious Trojan.Win.Z.Quasar.3638272
Webroot malicious Win.Backdoor.Quasar
ZoneAlarm malicious Troj/Quasar-AF

Details From VirusTotal

Basic Properties
MD5c4980a5b654f206a00806822b09029ee
SHA-15cd05132c8f5487bd9869c976358fc321a7b20fc
SHA-256539f53d61ace3821e6b78f54600e7ee6b87b170de9d96ece7c152328ff0959d6
VHash236036651516102d31ffff221e5bc6
SSDEEP98304:Zvlf82dHaW3ZVPBlZZBjdj6cXdxyRJ68k:NlJkcIZk
TLSHT1A8F53A1437F87E26E1AAE27797B0043267F0EC1AA363E70B25C166E93C5F75058316A7
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size3.5 MB
History
Creation date2023-03-12 16:16 UTC
First seen on VirusTotal2026-05-15 10:54 UTC
Last submission2026-05-17 10:57 UTC
Last analysis2026-06-22 12:35 UTC
Last modified on VirusTotal2026-06-23 19:14 UTC
Known Names
  • cliphot69
  • 539f53d61ace3821e6b78f54600e7ee6b87b170de9d96ece7c152328ff0959d6.exe
  • cliphot69.exe
  • 69628d.exe
hash_md5 c4980a5b654f206a00806822b09029ee VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/c4980a5b654f206a00806822b09029ee
1 feed

IOC database

Type
hash_md5
Value
c4980a5b654f206a00806822b09029ee
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/c4980a5b654f206a00806822b09029ee

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 3638272 bytes. Tags: exe, QUASARRAT, rat. Reporter: cleanabuseweb. First seen: 2026-05-15 11:37:08.

Remediations (10)

  • web:7orvs.github.io

    QuasarRAT Analysis pt1 4 minute read On this page QuasarRAT Analysis General Inoformation: Basic Static Analysis Basic Dynamic Analysis Advanced analysis QuasarRAT Analysis General Inoformation: ... Basic Static Analysis The output from DIE told us that this sample is written in .NET with high entropy and packing indication:

  • web:any.run

    Quasar is a remote access trojan is used by attackers to take remote control of infected machines. Follow live malware statistics of this trojan and get new reports, samples, IOCs, etc.

  • web:asec.ahnlab.com

    The code ultimately injected into "explorer.exe" is xRAT ( QuasarRAT ), which performs various malicious behaviors such as collecting system information, keylogging, and downloading and uploading files.

  • web:bazaar.abuse.ch

    QuasarRAT malware samples MalwareBazaar Database MalwareBazaar tries to identify the malware family (signature) of submitted malware samples. A malware sample can be associated with only one malware family. The page below gives you an overview on malware samples that MalwareBazaar has identified as QuasarRAT . Database Entry

  • web:cybersecuritynews.com

    A dangerous malware threat has emerged targeting Windows users across Korea through webhard file-sharing services. The Ahnlab Security Intelligence Center recently identified xRAT, also known as QuasarRAT , being distributed as fake adult games to unsuspecting users.

  • web:github.com

    QuasarRAT Free, Open-Source Remote Administration Tool for Windows Quasar is a fast and light-weight remote administration tool coded in C#. Providing high stability and an easy-to-use user interface, Quasar is the perfect remote administration solution for you.

  • web:pentesttools.net

    Quasar is a fast and light-weight remote administration tool coded in C#. Providing high stability and an easy-to-use user interface, Quasar is the perfect remote administration solution for you.

  • web:www.microsoft.com

    Following the mitigation steps below can help prevent hack tool attacks. Keep backups so you can recover data affected by trojans and destructive attacks. Use controlled folder access to prevent unauthorized applications from modifying protected files. Harden internet-facing assets and ensure they have the latest security updates.

  • web:www.pcrisk.com

    Manual malware removal is a complicated task - usually it is best to allow antivirus or anti-malware programs to do this automatically. To remove this malware we recommend using Combo Cleaner Antivirus for Windows. If you wish to remove malware manually, the first step is to identify the name of the malware that you are trying to remove.

  • web:www.yazoul.net

    How to remove QuasarRAT malware. Step-by-step containment, removal, and verification. Covers persistence, dropped files, and post-removal hardening.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.