s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1812064 high

📛 Threat Title

Quasar RAT: Domain name that delivers a malware payload hitclubx.im

Category: Quasar RAT Published: Source updated: First seen: Last updated: Source: Threatfox IOCs/Threats

Description

Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Quasar RAT (aliases: CinaRAT,QuasarRAT,Yggdrasil). Confidence: 75. First seen: 2026-05-14 03:35:32 UTC. Reporter: haruharu.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 104.18.26.60 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.18.26.60

IOC database

Type
ipv4
Value
104.18.26.60
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain hitclubx.im

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.18.26.60

ipv4 104.18.27.60 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.18.27.60

IOC database

Type
ipv4
Value
104.18.27.60
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain hitclubx.im

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.18.27.60

domain hitclubx.im UrlVoid 4 / 35

IOC database

Type
domain
Value
hitclubx.im
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Domain name that delivers a malware payload attributed to Quasar RAT

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • Malpedia profile Threatfox IOCs/Threats
  • ThreatFox IOC page Threatfox IOCs/Threats

    Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Quasar RAT (aliases: CinaRAT,QuasarRAT,Yggdrasil). Confidence: 75. First seen: 2026-05-14 03:35:32 UTC. Reporter: haruharu.

  • External reference Threatfox IOCs/Threats

Remediations (10)

  • web:any.run

    Quasar is a remote access trojan is used by attackers to take remote control of infected machines. Follow live malware statistics of this trojan and get new reports, samples, IOCs, etc.

  • web:community.netwitness.com

    There are several distribution methods for QuasarRAT—it is most commonly spread via malspam, and there are additional examples of threat actors dropping Quasar by exploiting publicly disclosed vulnerabilities and packing the malware as a secondary payload post-initial compromise. QuasarRAT operates in a client-server model (i).

  • web:corelight.com

    This month, we develop signatures that detect Quasar , a popular Windows-based remote access tool that has been abused for malware infections in the wild since 2014. Quasar was the #9 most-seen malware family in Q1-Q2 2024 by Spamhaus, and its variants have been used in 2024 attacks against financial institutions in Latin America.

  • web:cyberint.com

    The risks of Quasar RAT infection include unauthorized access to personal and financial information, loss of data, compromise of important accounts, installation of additional malware , and potential damage to the computer system.

  • web:cyberpress.org

    The use of image files for payload delivery helps bypass security tools that do not deeply inspect the data content of common file formats. After establishing a foothold with Quasar RAT , the malware ensures persistence by creating a Windows scheduled task.

  • web:gbhackers.com

    In the second installment of the "Advent of Configuration Extraction" series, security researchers have unwrapped QuasarRAT , a widely-deployed .NET remote access trojan ( RAT ), revealing sophisticated techniques for extracting its encrypted configuration from both clean and obfuscated binary samples.

  • web:hunt.io

    Explore Quasar RAT , an open-source remote access trojan used in cyber espionage. Learn about its features, distribution, and mitigation strategies.

  • web:www.botconf.eu

    The Quasar family malware has been used in many attack cases. It is important to understand the details of the Quasar RAT and its family, particularly how each project develops from the QuasarRAT and is being used for new types of attacks.

  • web:www.cybermaterial.com

    Quasar RAT is an open-source malware that has gained notoriety for its dual-use capabilities. Developed in C# and publicly hosted on GitHub, Quasar allows legitimate users, such as IT professionals, to access and manage remote systems.

  • web:www.splunk.com

    Uncover how to identify malicious executable loaders that use steganography to deliver payloads such as Quasar RAT .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…