s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1811893 high

📛 Threat Title

Quasar RAT: Domain that is used for botnet Command&control (C&C) uu888.jp.net

Category: Quasar RAT First seen: Last updated: Source: Threatfox IOCs/Threats

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Quasar RAT (aliases: CinaRAT,QuasarRAT,Yggdrasil). Confidence: 75. First seen: 2026-05-13 17:11:12 UTC. Reporter: abuse_ch. Tags: quasar.

Indicators of Compromise (2)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 36.50.177.13 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/36.50.177.13

IOC database

Type
ipv4
Value
36.50.177.13
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain uu888.jp.net

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/36.50.177.13

domain uu888.jp.net UrlVoid 4 / 35

IOC database

Type
domain
Value
uu888.jp.net
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Domain that is used for botnet Command&control (C&C) attributed to Quasar RAT

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • External reference Threatfox IOCs/Threats
  • Malpedia profile Threatfox IOCs/Threats
  • ThreatFox IOC page Threatfox IOCs/Threats

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Quasar RAT (aliases: CinaRAT,QuasarRAT,Yggdrasil). Confidence: 75. First seen: 2026-05-13 17:11:12 UTC. Reporter: abuse_ch. Tags: quasar.

Remediations (10)

  • web:any.run

    Quasar is a remote access trojan is used by attackers to take remote control of infected machines. Follow live malware statistics of this trojan and get new reports, samples, IOCs, etc.

  • web:corelight.com

    Our approach leverages Quasar's default configuration options when using self-signed TLS certificates. By default, Quasar uses the hard-coded TLS common name (CN) " Quasar Server CA ", as seen in its open-source repository. When a client connects to this server using a TLS connection for command-and-control, the server will present its CN in cleartext, which Suricata ® signatures or ...

  • web:cyberint.com

    Introduction Quasar , crafted in the C# programming language, is a publicly accessible and open-source Remote Access Trojan ( RAT ) designed for Microsoft Windows operating systems (OSs). This creation comes courtesy of the GitHub user MaxXor and resides as a publicly hosted repository on GitHub. While its utility extends to legitimate applications like enabling remote assistance from an ...

  • web:cybersight-security.github.io

    Quasar is typically spread through phishing emails, malicious downloads, or exploiting software vulnerabilities. Once installed on a victim's system, it establishes a covert connection to a remote command and control (C&C) server, allowing attackers to execute commands, steal sensitive data, or deploy additional malware.

  • web:medium.com

    QuasarRAT Malware Analysis Report Introduction QuasarRAT is an open-source RAT (Remote Access Tool/Trojan). These tools are built for legitimate purposes like accessing remote computers, e.g ...

  • web:www.darktrace.com

    Discover how the Quasar remote access tool can become a vulnerability in the wrong hands and strategies to mitigate these risks.

  • web:www.embeeresearch.io

    Extraction of Quasar C2 configuration via Dnspy, and using this information to pivot to additional servers utilising Shodan and Censys.

  • web:www.immersivelabs.com

    In this article, we will will take you through the process of analysing a Quasar RAT sample and discuss our decisions. When analysing a suspected RAT , the first thing an incident response team wish to know is the command and control centre's domain .

  • web:www.pcrisk.com

    Quasar malware overview Quasar can be used to access Task Manager, Registry Editor, manage files and startup items, download/upload and execute files, access system information, run various computer commands, log keystrokes, steal passwords and access files stored on the computer. It is a powerful tool that can cause serious problems.

  • web:www.trendmicro.com

    TrendAI™ Research breaks down Quasar Linux (QLNX), a previously undocumented sophisticated Linux RAT with low detection rates. In this blog, we examine a full-featured Linux threat incorporating a rootkit, a PAM backdoor, credential harvesting, and more, revealing how this malware enables stealthy access, persistence, and potential supply-chain attacks.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…