TF-1812064
high
📛 Threat Title
Quasar RAT: Domain name that delivers a malware payload hitclubx.im
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Quasar RAT (aliases: CinaRAT,QuasarRAT,Yggdrasil). Confidence: 75. First seen: 2026-05-14 03:35:32 UTC. Reporter: haruharu.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
104.18.26.60
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.18.26.60
IOC database
- Type
- ipv4
- Value
104.18.26.60- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from domain hitclubx.im
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.18.26.60
ipv4
104.18.27.60
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.18.27.60
IOC database
- Type
- ipv4
- Value
104.18.27.60- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from domain hitclubx.im
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.18.27.60
domain
hitclubx.im
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
hitclubx.im- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain name that delivers a malware payload attributed to Quasar RAT
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Quasar RAT (aliases: CinaRAT,QuasarRAT,Yggdrasil). Confidence: 75. First seen: 2026-05-14 03:35:32 UTC. Reporter: haruharu.
- External reference Threatfox IOCs/Threats
Remediations (10)
-
web:any.run
Quasar is a remote access trojan is used by attackers to take remote control of infected machines. Follow live malware statistics of this trojan and get new reports, samples, IOCs, etc.
-
web:community.netwitness.com
There are several distribution methods for QuasarRAT—it is most commonly spread via malspam, and there are additional examples of threat actors dropping Quasar by exploiting publicly disclosed vulnerabilities and packing the malware as a secondary payload post-initial compromise. QuasarRAT operates in a client-server model (i).
-
web:corelight.com
This month, we develop signatures that detect Quasar , a popular Windows-based remote access tool that has been abused for malware infections in the wild since 2014. Quasar was the #9 most-seen malware family in Q1-Q2 2024 by Spamhaus, and its variants have been used in 2024 attacks against financial institutions in Latin America.
-
web:cyberint.com
The risks of Quasar RAT infection include unauthorized access to personal and financial information, loss of data, compromise of important accounts, installation of additional malware , and potential damage to the computer system.
-
web:cyberpress.org
The use of image files for payload delivery helps bypass security tools that do not deeply inspect the data content of common file formats. After establishing a foothold with Quasar RAT , the malware ensures persistence by creating a Windows scheduled task.
-
web:gbhackers.com
In the second installment of the "Advent of Configuration Extraction" series, security researchers have unwrapped QuasarRAT , a widely-deployed .NET remote access trojan ( RAT ), revealing sophisticated techniques for extracting its encrypted configuration from both clean and obfuscated binary samples.
-
web:hunt.io
Explore Quasar RAT , an open-source remote access trojan used in cyber espionage. Learn about its features, distribution, and mitigation strategies.
-
web:www.botconf.eu
The Quasar family malware has been used in many attack cases. It is important to understand the details of the Quasar RAT and its family, particularly how each project develops from the QuasarRAT and is being used for new types of attacks.
-
web:www.cybermaterial.com
Quasar RAT is an open-source malware that has gained notoriety for its dual-use capabilities. Developed in C# and publicly hosted on GitHub, Quasar allows legitimate users, such as IT professionals, to access and manage remote systems.
-
web:www.splunk.com
Uncover how to identify malicious executable loaders that use steganography to deliver payloads such as Quasar RAT .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.