s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-a497a5a4aee23b53de957e253ba57b4d0ba7fecf0b2d8eccf237898a0de5ff38 high

📛 Threat Title

NetSupport: 147.45.45.245.msi

Category: NetSupport Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: msi. Size: 2330624 bytes. Tags: 147-45-45-245, 95-85-246-222, baracudamin-com, host-netsup-com, msi, NetSupport. Reporter: JAMESWT_WT. First seen: 2026-05-15 05:56:31.

Indicators of Compromise (5)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 147.45.45.245 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/147.45.45.245
1 feed

IOC database

Type
ipv4
Value
147.45.45.245
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Imported from threat-intel feed: threatview.io

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/147.45.45.245

domain 147.45.45.245.msi VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/147.45.45.245.msi

IOC database

Type
domain
Value
147.45.45.245.msi
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat MB-a497a5a4aee23b53de957e253ba57b4d0ba7fecf0b2d8eccf237898a0de5ff38

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/147.45.45.245.msi

hash_sha256 a497a5a4aee23b53de957e253ba57b4d0ba7fecf0b2d8eccf237898a0de5ff38 1 feed

IOC database

Type
hash_sha256
Value
a497a5a4aee23b53de957e253ba57b4d0ba7fecf0b2d8eccf237898a0de5ff38
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
NetSupport

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 12c71c65cb1f17e9ab850eda2e59858851233f83 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/12c71c65cb1f17e9ab850eda2e59858851233f83
1 feed

IOC database

Type
hash_sha1
Value
12c71c65cb1f17e9ab850eda2e59858851233f83
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/12c71c65cb1f17e9ab850eda2e59858851233f83

hash_md5 1b20fc24126bf5dbf907b48dc7a799f5 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/1b20fc24126bf5dbf907b48dc7a799f5
1 feed

IOC database

Type
hash_md5
Value
1b20fc24126bf5dbf907b48dc7a799f5
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/1b20fc24126bf5dbf907b48dc7a799f5

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: msi. Size: 2330624 bytes. Tags: 147-45-45-245, 95-85-246-222, baracudamin-com, host-netsup-com, msi, NetSupport. Reporter: JAMESWT_WT. First seen: 2026-05-15 05:56:31.

Remediations (10)

  • web:any.run

    NetSupport Manager, developed in 1989, is a legitimate remote administration tool designed for technical support. It enables file transfers, support chat, inventory management, and remote access.

  • web:blackpointcyber.com

    Explore how Blackpoint Cyber's SOC responded to PowerShell, Zoho Assist, and NetSupport RAT attacks, with key insights and mitigation strategies for protection.

  • web:blogs.vmware.com

    This means it can recognize known indicators of compromise associated with NetSupport RAT, enabling quick identification and mitigation of infected systems. Endpoint Security: Carbon Black provides robust endpoint security features, ensuring that devices are protected at the point of entry.

  • web:botcrawl.com

    NetSupport Client Application (also called NetSupport Manager) by NetSupport Ltd. is cross platform remote control software that can monitor screens and multiple systems in real time. This removal guide will help you remove the NetSupport Client Application Trojan.

  • web:cyberpress.org

    Cybersecurity researchers have reported a significant increase in the use of the NetSupport Remote Access Trojan (RAT) since early January 2025. Originally developed as a legitimate remote IT support tool under the name NetSupport Manager, this software has been weaponized by threat actors to infiltrate systems, enabling full remote control over compromised devices. The ongoing campaign, which ...

  • web:forums.malwarebytes.com

    Let's go ahead and run a few scans and get some logs from your system. Please read the entire post below before starting so that you're more familiar with the process Please do all of the requested scans in order and attach all of the results in your next reply.<<<<< Important. Please respond to all future instructions from your helper in a timely manner. Please make the following system ...

  • web:github.com

    NetSupportRemover This repository contains two Windows batch scripts designed for system administrators or users who need to terminate specific processes and uninstall NetSupport efficiently. These scripts are particularly useful for automating the process of uninstalling NetSupport .

  • web:kb.netsupportsoftware.com

    In cases like this, you can still deploy our software and instruct the .msi installer what components of the software to install by using parameters when executing the installer.

  • web:support.microsoft.com

    Describes the .NET Framework Repair Tool and how to obtain it.

  • web:www.pcrisk.com

    The NetSupport Manager program is categorized as a Remote Access Tool (RAT). Like most programs of this type, it allow users to access computers, workstations, and servers locally and remotely.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…