s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

OTX-686e30b828d2b9a95e8e7b38 high

📛 Threat Title

NetBus Trojan - C2 IP/Domain Tracker

Category: NetBus Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

This pulse contains IOCs related to NetBus Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 201.71.24.73 VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/201.71.24.73

IOC database

Type
ipv4
Value
201.71.24.73
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/201.71.24.73

ipv4 216.144.234.251 VT 10 / 91

IOC database

Type
ipv4
Value
216.144.234.251
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 10 of 91 VirusTotal vendors

VendorVerdictDetection
alphaMountain.ai malicious malicious
AlphaSOC malicious malware
BitDefender malicious malware
Chong Lua Dao malicious malicious
CyRadar malicious malware
G-Data malicious malware
Lionic malicious malware
SOCRadar malicious malicious
Sophos malicious malware
Gridinsoft suspicious suspicious

Details From VirusTotal

Basic Properties
Network216.144.232.0/21
CountryUS
AS ownerHostPapa
ASN36352
Regional registryARIN
History
Last analysis2026-07-07 21:47 UTC
Last modified on VirusTotal2026-07-16 13:04 UTC
WHOIS record date2026-07-10 22:39 UTC

ipv4 109.123.239.180

IOC database

Type
ipv4
Value
109.123.239.180
First seen
Last seen
Attached to this threat
Appears in
4 threats
Description
ip:port combination that is used for botnet Command&control (C&C) attributed to NetSupportManager RAT

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • OTX pulse AlienVaulkt OTX

    This pulse contains IOCs related to NetBus Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.

Remediations (8)

  • web:cyberpress.org

    Cybersecurity researchers have reported a significant increase in the use of the NetSupport Remote Access Trojan (RAT) since early January 2025. Originally developed as a legitimate remote IT support tool under the name NetSupport Manager, this software has been weaponized by threat actors to infiltrate systems, enabling full remote control over compromised devices. The ongoing campaign, which ...

  • web:cybersecuritynews.com

    Cybersecurity experts have observed a significant increase in the use of the NetSupport Remote Access Trojan (RAT) in recent months, a malicious tool that allows attackers to gain full control over compromised systems. This surge in activity has been linked to the "ClickFix" Initial Access Vector (IAV), a sophisticated social engineering technique that tricks users into executing malicious ...

  • web:en.wikipedia.org

    NetBus or Netbus is a software program for remotely controlling a Microsoft Windows computer system over a network. It was created in 1998 and has been very controversial for its potential to be used as a trojan horse. [1][2]

  • web:ethicalhacksacademy.com

    C2 Tracker is a free, community-driven Indicator of Compromise (IOC) feed designed to track IP addresses associated with known malware, botnets, and Command-and-Control ( C2 ) infrastructure.

  • web:github.com

    C2 Tracker is a free-to-use-community-driven IOC feed that uses Shodan and Censys searches to collect IP addresses of known malware/botnet/ C2 infrastructure.

  • web:threatfox.abuse.ch

    ThreatFox ThreatFox is a platform from abuse.ch and Spamhaus dedicated to sharing indicators of compromise (IOCs) associated with malware, with the infosec community, AV vendors and cyber threat intelligence providers. Upload IOCs and explore the database for valuable intelligence. Use the APIs to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain ...

  • web:www.esentire.com

    NetSupport RAT is a Remote Access Trojan (RAT) that is used by threat actors to gain control of the victim's host. It was originally developed as a remote IT support tool in 1989 and was known as NetSupport Manager but has been weaponized by cybercriminals in recent years.

  • web:www.pentestpad.com

    Port 12345 is notoriously associated with the NetBus trojan , one of the most well-known remote access trojans (RATs) from the late 1990s. If this port is open, it typically indicates either a compromised system or legitimate software using this port number.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…