s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

OTX-686e30616255e76d31a489ab high

📛 Threat Title

Orcus RAT Trojan - C2 IP/Domain Tracker

Category: Orcus RAT Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

This pulse contains IOCs related to Orcus RAT Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds. Pulse contains 1 indicator(s) (IOCs). View on OTX to inspect.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 193.222.99.85

IOC database

Type
ipv4
Value
193.222.99.85
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • OTX pulse AlienVaulkt OTX

    This pulse contains IOCs related to Orcus RAT Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.

Remediations (8)

  • web:any.run

    Orcus is a modular Remote Access Trojan that enables attackers to create plugins using a custom development library and offers a robust core feature set. Follow live statistics of this virus and get new reports, samples, IOCs, etc.

  • web:ethicalhacksacademy.com

    C2 Tracker is a free, community-driven Indicator of Compromise (IOC) feed designed to track IP addresses associated with known malware, botnets, and Command-and-Control ( C2 ) infrastructure.

  • web:github.com

    C2 Tracker is a free-to-use-community-driven IOC feed that uses Shodan and Censys searches to collect IP addresses of known malware/botnet/ C2 infrastructure.

  • web:hunt.io

    Orcus is a modular Remote Access Trojan with some unusual functions. This RAT enables attackers to create plugins using a custom development library and offers a robust core feature set that makes it one of the most dangerous malicious programs in its class.

  • web:intel.mjolnirsecurity.com

    Orcus RAT (also known as Orcus RAT , Orcus Technologies) is a C#/.NET-based remote access trojan active since 2016. Commercial RAT disguised as admin tool. Key capabilities include: HVNC, plugin system, webcam, keylogger, marketed as 'remote admin tool'.

  • web:sechub.in

    C2 Tracker Free to use IOC feed for various tools/malware. It started out for just C2 tools but has morphed into tracking infostealers and botnets as well. It uses Shodan searches to collect the IPs. The most recent collection is always stored in data; the IPs are broken down by tool and there is an all.txt. The feed should update daily.

  • web:threatfox.abuse.ch

    ThreatFox ThreatFox is a platform from abuse.ch and Spamhaus dedicated to sharing indicators of compromise (IOCs) associated with malware, with the infosec community, AV vendors and cyber threat intelligence providers. Upload IOCs and explore the database for valuable intelligence. Use the APIs to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain ...

  • web:www.rstcloud.com

    Our C2 Tracker offers critical insights into various sophisticated malware and C2 frameworks. With continuous updates, the tracker monitors C2 activities across a range of threats, including: RATs : Orcus RAT , AsyncRAT, VenomRAT, DcRat, Quasar RAT , VIPER RAT , Gh0st RAT , Pupy RAT , Ares RAT , XtremeRAT, Chaos RAT , SectopRAT, PlugX RAT , etc.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…