TF-1932723
high
📛 Threat Title
AsyncRAT: Domain that is used for botnet Command&control (C&C) qaqfahai.com
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: AsyncRAT. Confidence: 75. First seen: 2026-09-25 08:10:33 UTC. Reporter: abuse_ch. Tags: asyncrat.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
qaqfahai.com
VT 6 / 91
UrlVoid 3 / 36
IOC database
- Type
- domain
- Value
qaqfahai.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 6 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| CRDF | malicious | malicious |
| ESET | malicious | malware |
| Fortinet | malicious | malware |
| Gridinsoft | malicious | malicious |
| SOCRadar | malicious | malware |
| alphaMountain.ai | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | TUCOWS.COM, CO. |
| TLD | com |
History
| Creation date | 2026-09-02 03:50 UTC |
| Last analysis | 2026-09-22 10:14 UTC |
| Last modified on VirusTotal | 2026-09-25 17:13 UTC |
| Last WHOIS update | 2026-09-02 03:54 UTC |
| WHOIS record date | 2026-09-05 13:02 UTC |
References (3)
- External reference ThreatFox IOCs
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: AsyncRAT. Confidence: 75. First seen: 2026-09-25 08:10:33 UTC. Reporter: abuse_ch. Tags: asyncrat.
Remediations (10)
-
web:blog.qualys.com
In this blog we describe the AsyncRAT C2 (command & control) Framework, which allows attackers to remotely monitor and control other computers over a secure encrypted link. We provide an overview of this threat, a technical analysis, and a method of detecting the malware using Qualys Multi-Vector EDR. What is AsyncRAT C2 Framework?
-
web:censys.com
The malware supports remote command execution, file transfer, keylogging, screen capture, and credential harvesting, typically communicating with command-and-control (C2) servers over a custom TCP protocol with traffic encrypted via SSL/TLS, often using self-signed certificates that may present CN=AsyncRAT Server.
-
web:mssplab.github.io
AsyncRAT is a Remote Access Trojan (RAT) designed to remotely monitor and control infected systems. It is free, open-source, and often used by cybercriminals for malicious purposes, such as stealing sensitive information, installing more malware, or performing DDoS attacks.
-
web:socprime.com
Abstract or unrelated examples will lead to misdiagnosis. Attack Narrative & Commands: An adversary has gained initial access and is preparing to establish a persistent Command-and-Control (C2) channel using AsyncRAT . To evade network-based signature detection, the attacker utilizes the RijndaelManaged .NET class to encrypt the traffic.
-
web:threatfox.abuse.ch
AsyncRAT IOC: qaqfahai.com ( domain ) ThreatFox IOC Database You are viewing the ThreatFox database entry for domain qaqfahai.com .
-
web:www.checkpoint.com
Introduction to AsyncRAT A shortening of "Asynchronous Remote Access Trojan," AsyncRAT is a popular malware family used by a range of threat actors to target Windows systems. Remote access trojans are a type of malware that enables attackers to remotely control infected computers. Once the system is compromised, the attacker can execute commands remotely and receive data to facilitate ...
-
web:www.huntress.com
AsyncRAT is a remote access trojan that enables attackers to control victim systems, steal data, and monitor activity. It works by embedding itself into target machines, often via phishing emails, and communicating with a command-and-control server to execute malicious actions.
-
web:www.pointwild.com
Successive stages decrypt to a final AsyncRAT DLL (Veukuzmw.dll) with screen capture and information stealing functionality. The final payload is a recognizable AsyncRAT build with screen capture and command-and-control capability. Each stage is examined in sequence below, with the payload recovered statically at every step.
-
web:www.trendaisecurity.com
Analyzing a Multi-Stage AsyncRAT Campaign via Managed Detection and Response Threat actors exploited Cloudflare's free-tier infrastructure and legitimate Python environments to deploy the AsyncRAT remote access trojan, demonstrating advanced evasion techniques that abuse trusted cloud services for malicious operations.
-
web:www.zerosday.com
AsyncRAT Analysis: Deep Dive into a Versatile Remote Access Trojan This report provides a comprehensive technical analysis of AsyncRAT , a popular open-source Remote Access Trojan (RAT) frequently observed in various cyber-attack campaigns. We delve into its infection vectors, persistence mechanisms, Command and Control (C2) communication, and advanced anti-analysis techniques. This analysis is ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.