ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain duo.us.com.

Database Entry


IOC ID:1736888
IOC: duo.us.com
IOC Type :domain
Threat Type :botnet_cc
Malware: Quasar RAT
Malware alias:CinaRAT, QuasarRAT, Yggdrasil
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS13335 CLOUDFLARENET
Country:- US
First seen:2026-01-24 22:35:32 UTC
Last seen:2026-02-07 11:52:44 UTC
UUID:fe288424-f974-11f0-b7d0-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:quasar
Reference: https://bazaar.abuse.ch/sample/330dd5ab41b99540bb69e0531456ec2c3a3aa3663e39310825df186c2f937449/

Avatar
abuse_ch
quasar (aka CinaRAT,QuasarRAT,Yggdrasil) botnet C2 on port 1604 TCP