MB-a497a5a4aee23b53de957e253ba57b4d0ba7fecf0b2d8eccf237898a0de5ff38
high
📛 Threat Title
NetSupport: 147.45.45.245.msi
Description
File type: msi. Size: 2330624 bytes. Tags: 147-45-45-245, 95-85-246-222, baracudamin-com, host-netsup-com, msi, NetSupport. Reporter: JAMESWT_WT. First seen: 2026-05-15 05:56:31.
Indicators of Compromise (5)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
147.45.45.245
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/147.45.45.245
1 feed
IOC database
- Type
- ipv4
- Value
147.45.45.245- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Imported from threat-intel feed: threatview.io
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/147.45.45.245
domain
147.45.45.245.msi
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/147.45.45.245.msi
IOC database
- Type
- domain
- Value
147.45.45.245.msi- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat MB-a497a5a4aee23b53de957e253ba57b4d0ba7fecf0b2d8eccf237898a0de5ff38
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/147.45.45.245.msi
hash_sha256
a497a5a4aee23b53de957e253ba57b4d0ba7fecf0b2d8eccf237898a0de5ff38
1 feed
IOC database
- Type
- hash_sha256
- Value
a497a5a4aee23b53de957e253ba57b4d0ba7fecf0b2d8eccf237898a0de5ff38- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- NetSupport
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
12c71c65cb1f17e9ab850eda2e59858851233f83
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/12c71c65cb1f17e9ab850eda2e59858851233f83
1 feed
IOC database
- Type
- hash_sha1
- Value
12c71c65cb1f17e9ab850eda2e59858851233f83- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/12c71c65cb1f17e9ab850eda2e59858851233f83
hash_md5
1b20fc24126bf5dbf907b48dc7a799f5
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/1b20fc24126bf5dbf907b48dc7a799f5
1 feed
IOC database
- Type
- hash_md5
- Value
1b20fc24126bf5dbf907b48dc7a799f5- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/1b20fc24126bf5dbf907b48dc7a799f5
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: msi. Size: 2330624 bytes. Tags: 147-45-45-245, 95-85-246-222, baracudamin-com, host-netsup-com, msi, NetSupport. Reporter: JAMESWT_WT. First seen: 2026-05-15 05:56:31.
Remediations (10)
-
web:any.run
NetSupport Manager, developed in 1989, is a legitimate remote administration tool designed for technical support. It enables file transfers, support chat, inventory management, and remote access.
-
web:blackpointcyber.com
Explore how Blackpoint Cyber's SOC responded to PowerShell, Zoho Assist, and NetSupport RAT attacks, with key insights and mitigation strategies for protection.
-
web:blogs.vmware.com
This means it can recognize known indicators of compromise associated with NetSupport RAT, enabling quick identification and mitigation of infected systems. Endpoint Security: Carbon Black provides robust endpoint security features, ensuring that devices are protected at the point of entry.
-
web:botcrawl.com
NetSupport Client Application (also called NetSupport Manager) by NetSupport Ltd. is cross platform remote control software that can monitor screens and multiple systems in real time. This removal guide will help you remove the NetSupport Client Application Trojan.
-
web:cyberpress.org
Cybersecurity researchers have reported a significant increase in the use of the NetSupport Remote Access Trojan (RAT) since early January 2025. Originally developed as a legitimate remote IT support tool under the name NetSupport Manager, this software has been weaponized by threat actors to infiltrate systems, enabling full remote control over compromised devices. The ongoing campaign, which ...
-
web:forums.malwarebytes.com
Let's go ahead and run a few scans and get some logs from your system. Please read the entire post below before starting so that you're more familiar with the process Please do all of the requested scans in order and attach all of the results in your next reply.<<<<< Important. Please respond to all future instructions from your helper in a timely manner. Please make the following system ...
-
web:github.com
NetSupportRemover This repository contains two Windows batch scripts designed for system administrators or users who need to terminate specific processes and uninstall NetSupport efficiently. These scripts are particularly useful for automating the process of uninstalling NetSupport .
-
web:kb.netsupportsoftware.com
In cases like this, you can still deploy our software and instruct the .msi installer what components of the software to install by using parameters when executing the installer.
-
web:support.microsoft.com
Describes the .NET Framework Repair Tool and how to obtain it.
-
web:www.pcrisk.com
The NetSupport Manager program is categorized as a Remote Access Tool (RAT). Like most programs of this type, it allow users to access computers, workstations, and servers locally and remotely.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.