TF-1932776
high
📛 Threat Title
AsyncRAT: Domain that is used for botnet Command&control (C&C) as.bulkz.sbs
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: AsyncRAT. Confidence: 75. First seen: 2026-09-25 10:00:29 UTC. Reporter: abuse_ch. Tags: asyncrat.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
as.bulkz.sbs
UrlVoid 2 / 36
IOC database
- Type
- domain
- Value
as.bulkz.sbs- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain that is used for botnet Command&control (C&C) attributed to AsyncRAT
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- External reference ThreatFox IOCs
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: AsyncRAT. Confidence: 75. First seen: 2026-09-25 10:00:29 UTC. Reporter: abuse_ch. Tags: asyncrat.
Remediations (10)
-
web:blog.checkpoint.com
Researchers reported on a new AsyncRAT campaign where malicious HTML files were being used to spread the stealthy malware. Meanwhile, downloader FakeUpdates jumped straight into second place after a short break from the top ten list Our latest Global Threat Index for November 2023 saw researchers discover a AsyncRAT campaign where malicious HTML files were used to spread the covert malware ...
-
web:blog.qualys.com
In this blog we describe the AsyncRAT C2 (command & control) Framework, which allows attackers to remotely monitor and control other computers over a secure encrypted link. We provide an overview of this threat, a technical analysis, and a method of detecting the malware using Qualys Multi-Vector EDR. What is AsyncRAT C2 Framework?
-
web:censys.com
The malware supports remote command execution, file transfer, keylogging, screen capture, and credential harvesting, typically communicating with command-and-control (C2) servers over a custom TCP protocol with traffic encrypted via SSL/TLS, often using self-signed certificates that may present CN=AsyncRAT Server.
-
web:cyberint.com
Introduced in 2019, AsyncRAT is classified as a remote access trojan (RAT) that primarily functions as a tool for stealing credentials and loading various malware, including ransomware. This RAT boasts botnet capabilities and features a command and control (C2) interface, granting operators the ability to manipulate infected hosts from a remote location. Despite its official GitHub page ...
-
web:github.com
AsyncRAT is a Remote Access Tool (RAT) designed to remotely monitor and control other computers through a secure encrypted connection
-
web:www.checkpoint.com
Introduction to AsyncRAT A shortening of "Asynchronous Remote Access Trojan," AsyncRAT is a popular malware family used by a range of threat actors to target Windows systems. Remote access trojans are a type of malware that enables attackers to remotely control infected computers.
-
web:www.cloudsek.com
AsyncRAT is an open-source remote access trojan that gives attackers persistent control of Windows systems after phishing-based initial access.
-
web:www.extrahop.com
AsyncRAT and AsyncRAT variants are open-source malware that are easily accessible to attackers. This malware infects systems through user interaction, such as clicking phishing links or malicious ads. After a device is compromised, an attacker can remotely control the device, move laterally, or deploy secondary payloads and exfiltrate sensitive business information from the victim.
-
web:www.huntress.com
AsyncRAT is a remote access trojan that enables attackers to control victim systems, steal data, and monitor activity. It works by embedding itself into target machines, often via phishing emails, and communicating with a command-and-control server to execute malicious actions.
-
web:www.microsoft.com
Communication with command-and-control (C2) servers occurs over custom TCP ports, using efficient serialization for data exfiltration and device reconnaissance. Its core functionality encompasses comprehensive surveillance and system manipulation, including keylogging, audio/video recording, file theft, and remote shell access.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.