TF-1811893
high
📛 Threat Title
Quasar RAT: Domain that is used for botnet Command&control (C&C) uu888.jp.net
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Quasar RAT (aliases: CinaRAT,QuasarRAT,Yggdrasil). Confidence: 75. First seen: 2026-05-13 17:11:12 UTC. Reporter: abuse_ch. Tags: quasar.
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
36.50.177.13
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/36.50.177.13
IOC database
- Type
- ipv4
- Value
36.50.177.13- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from domain uu888.jp.net
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/36.50.177.13
domain
uu888.jp.net
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
uu888.jp.net- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain that is used for botnet Command&control (C&C) attributed to Quasar RAT
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- External reference Threatfox IOCs/Threats
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Quasar RAT (aliases: CinaRAT,QuasarRAT,Yggdrasil). Confidence: 75. First seen: 2026-05-13 17:11:12 UTC. Reporter: abuse_ch. Tags: quasar.
Remediations (10)
-
web:any.run
Quasar is a remote access trojan is used by attackers to take remote control of infected machines. Follow live malware statistics of this trojan and get new reports, samples, IOCs, etc.
-
web:corelight.com
Our approach leverages Quasar's default configuration options when using self-signed TLS certificates. By default, Quasar uses the hard-coded TLS common name (CN) " Quasar Server CA ", as seen in its open-source repository. When a client connects to this server using a TLS connection for command-and-control, the server will present its CN in cleartext, which Suricata ® signatures or ...
-
web:cyberint.com
Introduction Quasar , crafted in the C# programming language, is a publicly accessible and open-source Remote Access Trojan ( RAT ) designed for Microsoft Windows operating systems (OSs). This creation comes courtesy of the GitHub user MaxXor and resides as a publicly hosted repository on GitHub. While its utility extends to legitimate applications like enabling remote assistance from an ...
-
web:cybersight-security.github.io
Quasar is typically spread through phishing emails, malicious downloads, or exploiting software vulnerabilities. Once installed on a victim's system, it establishes a covert connection to a remote command and control (C&C) server, allowing attackers to execute commands, steal sensitive data, or deploy additional malware.
-
web:medium.com
QuasarRAT Malware Analysis Report Introduction QuasarRAT is an open-source RAT (Remote Access Tool/Trojan). These tools are built for legitimate purposes like accessing remote computers, e.g ...
-
web:www.darktrace.com
Discover how the Quasar remote access tool can become a vulnerability in the wrong hands and strategies to mitigate these risks.
-
web:www.embeeresearch.io
Extraction of Quasar C2 configuration via Dnspy, and using this information to pivot to additional servers utilising Shodan and Censys.
-
web:www.immersivelabs.com
In this article, we will will take you through the process of analysing a Quasar RAT sample and discuss our decisions. When analysing a suspected RAT , the first thing an incident response team wish to know is the command and control centre's domain .
-
web:www.pcrisk.com
Quasar malware overview Quasar can be used to access Task Manager, Registry Editor, manage files and startup items, download/upload and execute files, access system information, run various computer commands, log keystrokes, steal passwords and access files stored on the computer. It is a powerful tool that can cause serious problems.
-
web:www.trendmicro.com
TrendAI™ Research breaks down Quasar Linux (QLNX), a previously undocumented sophisticated Linux RAT with low detection rates. In this blog, we examine a full-featured Linux threat incorporating a rootkit, a PAM backdoor, credential harvesting, and more, revealing how this malware enables stealthy access, persistence, and potential supply-chain attacks.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.