ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain nnwjaigh1h.localto.net.

Database Entry


IOC ID:1778606
IOC: nnwjaigh1h.localto.net
IOC Type :domain
Threat Type :botnet_cc
Malware: Quasar RAT
Malware alias:CinaRAT, QuasarRAT, Yggdrasil
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS31898 ORACLE-BMC-31898
Country:- US
First seen:2026-03-29 14:35:22 UTC
Last seen:2026-03-29 18:00:26 UTC
UUID:84bac82f-2b7c-11f1-9af6-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:quasar
Reference: https://bazaar.abuse.ch/sample/99994c18d34425aabf7316fd762be99dadc589eaf0801f8390beccff4db960aa/

Avatar
abuse_ch
quasar (aka CinaRAT,QuasarRAT,Yggdrasil) botnet C2 on port 8428 TCP