OTX-686e30b828d2b9a95e8e7b38
high
📛 Threat Title
NetBus Trojan - C2 IP/Domain Tracker
Description
This pulse contains IOCs related to NetBus Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
201.71.24.73
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/201.71.24.73
IOC database
- Type
- ipv4
- Value
201.71.24.73- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/201.71.24.73
ipv4
216.144.234.251
VT 10 / 91
IOC database
- Type
- ipv4
- Value
216.144.234.251- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 10 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alphaMountain.ai | malicious | malicious |
| AlphaSOC | malicious | malware |
| BitDefender | malicious | malware |
| Chong Lua Dao | malicious | malicious |
| CyRadar | malicious | malware |
| G-Data | malicious | malware |
| Lionic | malicious | malware |
| SOCRadar | malicious | malicious |
| Sophos | malicious | malware |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Network | 216.144.232.0/21 |
| Country | US |
| AS owner | HostPapa |
| ASN | 36352 |
| Regional registry | ARIN |
History
| Last analysis | 2026-07-07 21:47 UTC |
| Last modified on VirusTotal | 2026-07-16 13:04 UTC |
| WHOIS record date | 2026-07-10 22:39 UTC |
ipv4
109.123.239.180
IOC database
- Type
- ipv4
- Value
109.123.239.180- First seen
- Last seen
- Attached to this threat
- Appears in
- 4 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to NetSupportManager RAT
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
OTX pulse
AlienVaulkt OTX
This pulse contains IOCs related to NetBus Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.
Remediations (8)
-
web:cyberpress.org
Cybersecurity researchers have reported a significant increase in the use of the NetSupport Remote Access Trojan (RAT) since early January 2025. Originally developed as a legitimate remote IT support tool under the name NetSupport Manager, this software has been weaponized by threat actors to infiltrate systems, enabling full remote control over compromised devices. The ongoing campaign, which ...
-
web:cybersecuritynews.com
Cybersecurity experts have observed a significant increase in the use of the NetSupport Remote Access Trojan (RAT) in recent months, a malicious tool that allows attackers to gain full control over compromised systems. This surge in activity has been linked to the "ClickFix" Initial Access Vector (IAV), a sophisticated social engineering technique that tricks users into executing malicious ...
-
web:en.wikipedia.org
NetBus or Netbus is a software program for remotely controlling a Microsoft Windows computer system over a network. It was created in 1998 and has been very controversial for its potential to be used as a trojan horse. [1][2]
-
web:ethicalhacksacademy.com
C2 Tracker is a free, community-driven Indicator of Compromise (IOC) feed designed to track IP addresses associated with known malware, botnets, and Command-and-Control ( C2 ) infrastructure.
-
web:github.com
C2 Tracker is a free-to-use-community-driven IOC feed that uses Shodan and Censys searches to collect IP addresses of known malware/botnet/ C2 infrastructure.
-
web:threatfox.abuse.ch
ThreatFox ThreatFox is a platform from abuse.ch and Spamhaus dedicated to sharing indicators of compromise (IOCs) associated with malware, with the infosec community, AV vendors and cyber threat intelligence providers. Upload IOCs and explore the database for valuable intelligence. Use the APIs to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain ...
-
web:www.esentire.com
NetSupport RAT is a Remote Access Trojan (RAT) that is used by threat actors to gain control of the victim's host. It was originally developed as a remote IT support tool in 1989 and was known as NetSupport Manager but has been weaponized by cybercriminals in recent years.
-
web:www.pentestpad.com
Port 12345 is notoriously associated with the NetBus trojan , one of the most well-known remote access trojans (RATs) from the late 1990s. If this port is open, it typically indicates either a compromised system or legitimate software using this port number.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.