TF-1812056
high
📛 Threat Title
Quasar RAT: Domain name that delivers a malware payload viajesexpress.com.mx
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Quasar RAT (aliases: CinaRAT,QuasarRAT,Yggdrasil). Confidence: 75. First seen: 2026-05-14 03:24:55 UTC. Reporter: haruharu.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
104.18.14.229
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.18.14.229
IOC database
- Type
- ipv4
- Value
104.18.14.229- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from domain viajesexpress.com.mx
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.18.14.229
ipv4
104.18.15.229
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.18.15.229
IOC database
- Type
- ipv4
- Value
104.18.15.229- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from domain viajesexpress.com.mx
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.18.15.229
domain
viajesexpress.com.mx
VT 14 / 91
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
viajesexpress.com.mx- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain name that delivers a malware payload attributed to Quasar RAT
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 14 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ADMINUSLabs | malicious | malicious |
| alphaMountain.ai | malicious | phishing |
| BitDefender | malicious | malware |
| CRDF | malicious | malicious |
| CyRadar | malicious | phishing |
| G-Data | malicious | malware |
| Gridinsoft | malicious | phishing |
| Kaspersky | malicious | phishing |
| Lionic | malicious | malicious |
| SOCRadar | malicious | malware |
| Sophos | malicious | phishing |
| VIPRE | malicious | malware |
| Certego | suspicious | suspicious |
| ESET | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | GoDaddy.com |
| TLD | com.mx |
History
| Last analysis | 2026-06-12 12:41 UTC |
| Last modified on VirusTotal | 2026-06-12 12:52 UTC |
| WHOIS record date | 2026-06-04 13:15 UTC |
References (3)
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Quasar RAT (aliases: CinaRAT,QuasarRAT,Yggdrasil). Confidence: 75. First seen: 2026-05-14 03:24:55 UTC. Reporter: haruharu.
- External reference Threatfox IOCs/Threats
Remediations (10)
-
web:any.run
Quasar is a remote access trojan is used by attackers to take remote control of infected machines. Follow live malware statistics of this trojan and get new reports, samples, IOCs, etc.
-
web:corelight.com
This month, we develop signatures that detect Quasar , a popular Windows-based remote access tool that has been abused for malware infections in the wild since 2014. Quasar was the #9 most-seen malware family in Q1-Q2 2024 by Spamhaus, and its variants have been used in 2024 attacks against financial institutions in Latin America.
-
web:cyberint.com
The risks of Quasar RAT infection include unauthorized access to personal and financial information, loss of data, compromise of important accounts, installation of additional malware , and potential damage to the computer system.
-
web:cyberpress.org
The use of image files for payload delivery helps bypass security tools that do not deeply inspect the data content of common file formats. After establishing a foothold with Quasar RAT , the malware ensures persistence by creating a Windows scheduled task.
-
web:cybersecuritynews.com
Threat actors are using Windows batch files to deliver Quasar RAT in a new campaign that evades security and ensures persistent access.
-
web:gbhackers.com
"Goto" statements make the execution path confusing. Large sections are broken up with random comments and junk instructions to hinder code analysis. Bat Files to Deploy Quasar RAT The most notable feature in this campaign is its sandbox evasion. Before delivering its core payload , the malware checks what type of hard disk is present on the ...
-
web:hunt.io
Explore Quasar RAT , an open-source remote access trojan used in cyber espionage. Learn about its features, distribution, and mitigation strategies.
-
web:techowlshield.com
Our threat research analysis of Quasar Linux (QLNX) found a previously undocumented, full-featured Linux Remote Access Trojan. Despite sharing the " Quasar " name with the well-known open-source Windows RAT (C#/.NET), QLNX is an entirely separate native Linux implant purpose-built for one mission: compromising developer and DevOps workstations to ...
-
web:www.cybermaterial.com
Quasar RAT is an open-source malware that has gained notoriety for its dual-use capabilities. Developed in C# and publicly hosted on GitHub, Quasar allows legitimate users, such as IT professionals, to access and manage remote systems.
-
web:www.splunk.com
Uncover how to identify malicious executable loaders that use steganography to deliver payloads such as Quasar RAT .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.