s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1817824 high

📛 Threat Title

AsyncRAT: Domain that is used for botnet Command&control (C&C) dbpw.cn.com

Category: AsyncRAT Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: AsyncRAT. Confidence: 75. First seen: 2026-05-24 05:15:52 UTC. Reporter: abuse_ch. Tags: asyncrat.

Indicators of Compromise (2)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 34.76.205.124 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/34.76.205.124

IOC database

Type
ipv4
Value
34.76.205.124
First seen
Last seen
Attached to this threat
Appears in
27 threats
Description
Resolved from domain xpch.sa.com

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/34.76.205.124

domain dbpw.cn.com

IOC database

Type
domain
Value
dbpw.cn.com
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • External reference ThreatFox IOCs
  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: AsyncRAT. Confidence: 75. First seen: 2026-05-24 05:15:52 UTC. Reporter: abuse_ch. Tags: asyncrat.

Remediations (10)

  • web:blog.qualys.com

    In this blog we describe the AsyncRAT C2 (command & control) Framework, which allows attackers to remotely monitor and control other computers over a secure encrypted link. We provide an overview of this threat, a technical analysis, and a method of detecting the malware using Qualys Multi-Vector EDR. What is AsyncRAT C2 Framework?

  • web:censys.com

    The malware supports remote command execution, file transfer, keylogging, screen capture, and credential harvesting, typically communicating with command-and-control (C2) servers over a custom TCP protocol with traffic encrypted via SSL/TLS, often using self-signed certificates that may present CN=AsyncRAT Server.

  • web:corelight.com

    The example of AsyncRAT shows that all is not lost when malware uses HTTPS to communicate with its C2 server. In some cases, as we saw here, a default SSL certificate is used , and this server literally announces itself as a component of the AsyncRAT malware framework.

  • web:cyberint.com

    Introduced in 2019, AsyncRAT is classified as a remote access trojan (RAT) that primarily functions as a tool for stealing credentials and loading various malware, including ransomware. This RAT boasts botnet capabilities and features a command and control (C2) interface, granting operators the ability to manipulate infected hosts from a remote location. Despite its official GitHub page ...

  • web:mssplab.github.io

    AsyncRAT is a Remote Access Trojan (RAT) designed to remotely monitor and control infected systems. It is free, open-source, and often used by cybercriminals for malicious purposes, such as stealing sensitive information, installing more malware, or performing DDoS attacks.

  • web:www.activecountermeasures.com

    What is Malware of the Day? Lab Setup "Malware": AsyncRAT MITRE Tactics: TA0011 Command and Control , T1571 Non-Standard Port Traffic Type: TCP SSL Connection Type: Reverse TCP C2 Platform: AsyncRAT Origin of Sample: Active Countermeasures Lab Host Payload Delivery Method: EXE binary (C2 implant) Target Host/Victim: 192.168.100.136 (Windows 10 Enterprise x64) C2 Server: 172.208.51.75 ...

  • web:www.checkpoint.com

    Introduction to AsyncRAT A shortening of "Asynchronous Remote Access Trojan," AsyncRAT is a popular malware family used by a range of threat actors to target Windows systems. Remote access trojans are a type of malware that enables attackers to remotely control infected computers.

  • web:www.eset.com

    ESET Research has released insights into the landscape of AsyncRAT , a remote access tool (RAT), and its numerous variants.

  • web:www.huntress.com

    AsyncRAT is a remote access trojan that enables attackers to control victim systems, steal data, and monitor activity. It works by embedding itself into target machines, often via phishing emails, and communicating with a command-and-control server to execute malicious actions.

  • web:www.microsoft.com

    Trojan:BAT/ AsyncRat (Asynchronous Remote Access Trojan) is a sophisticated, feature-rich malware that provides threat actors with full remote control over compromised Windows devices. First published as open-source software on GitHub in 2019, its code has been weaponized and modified by a diverse range of threat actors. This open-source nature has made AsyncRAT a cornerstone of modern malware ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…