s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

OTX-6ab5bc147ae656c33dc21a39 high

📛 Threat Title

AsyncRAT - C2 IP/Domain Tracker - 2026-09-25

Category: AsyncRAT Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

This pulse contains IOCs related to AsyncRAT Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds. Due to the volume of indicators collected by this tracker, new pulses are created periodically. The timestamp in the title indicates when this pulse was created. Pulse contains 9 indicator(s) (IOCs). View on OTX to inspect.

Indicators of Compromise (9)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 45.88.91.165 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/ip_addresses/45.88.91.165

IOC database

Type
ipv4
Value
45.88.91.165
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
ip:port combination that is used for botnet Command&control (C&C) attributed to PureRAT

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/ip_addresses/45.88.91.165

domain azorult.xxxhay.tv UrlVoid 3 / 36

IOC database

Type
domain
Value
azorult.xxxhay.tv
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 149.33.21.9

IOC database

Type
ipv4
Value
149.33.21.9
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain xxxhay.tv

IOC database

Type
domain
Value
xxxhay.tv
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain hack.xxxhay.tv UrlVoid 3 / 36

IOC database

Type
domain
Value
hack.xxxhay.tv
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 135.0.47.98

IOC database

Type
ipv4
Value
135.0.47.98
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain hermeticwiper.xxxhay.tv UrlVoid 3 / 36

IOC database

Type
domain
Value
hermeticwiper.xxxhay.tv
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain www.xxxhay.tv UrlVoid 3 / 36

IOC database

Type
domain
Value
www.xxxhay.tv
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain mydoom.xxxhay.tv UrlVoid 3 / 36

IOC database

Type
domain
Value
mydoom.xxxhay.tv
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • OTX pulse AlienVaulkt OTX

    This pulse contains IOCs related to AsyncRAT Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds. Due to the volume of indicators collected by this tracker, new pulses are created periodically. The timestamp in the title indicates when this pulse was created.

Remediations (8)

  • web:any.run

    AsyncRAT is a remote access trojan that observes and administers infected machines. Follow live malware statistics of this downloader and get new reports, samples, IOCs, etc.

  • web:censys.com

    Discover Censys research on AsyncRAT—tracking 57+ active C2 servers via self-signed TLS certificates. Explore threat intelligence on this open-source RAT's infrastructure and capabilities.

  • web:censys.com

    Overview AsyncRAT is a family of open-source Windows remote access trojans (RATs): an original codebase that has been forked repeatedly into dozens of descendant malware families. Its most prolific descendant, DCRAT (also known as DarkCrystal RAT), spawned a second generation of forks of its own. Censys searches on 16 June 2026 confirmed live command-and-control ( C2 ) infrastructure for more ...

  • web:github.com

    C2 Tracker C2 Tracker is a free-to-use-community-driven IOC feed that uses Shodan and Censys searches to collect IP addresses of known malware/botnet/ C2 infrastructure.

  • web:github.com

    AsyncRAT Malware Analysis Comprehensive threat intelligence and detection package for AsyncRAT malware family.

  • web:meterpreter.org

    A pronounced escalation in the activity of infrastructure tethered to the AsyncRAT remote access trojan has been meticulously documented across the global network. Analysis of pervasive telemetry reveals that the command-and-control ( C2 ) servers of this lineage are being deployed en masse across accessible hosting environments, remaining a quintessential instrument for orchestrated incursions ...

  • web:www.yazoul.net

    AsyncRAT activity on 2026 -06-21 shows 20 new samples, an 18% decline from the 7-day average of 24. While sample volume is moderate, a surge of 100 new C2 servers signals possible infrastructure expansion or rotation.

  • web:www.yazoul.net

    AsyncRAT activity dropped sharply on 2026 - 09 -20, with 12 new samples against a 7-day average of 34, a 64% decline. The drop is broad-based rather than a single-family outage, but C2 infrastructure tells the opposite story: 99 new servers and 111 new IOCs appeared today even as sample volume fell.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…