ThreatFox IOC Database
You are viewing the ThreatFox database entry for ip:port 91.92.137.12:1604.
Database Entry
| IOC ID: | 1840400 |
|---|---|
| IOC: | 91.92.137.12:1604 |
| IOC Type : | ip:port |
| Threat Type : | botnet_cc |
| Malware: | Quasar RAT |
| Malware alias: | CinaRAT, QuasarRAT, Yggdrasil |
| Confidence Level : | Confidence level is elevated (75%) |
| Is compromised? : | False |
| ASN: | AS44901 belcloud |
| Country: | BG |
| First seen: | 2026-07-01 05:50:03 UTC |
| Last seen: | never |
| UUID: | f4c87cf7-74c4-11f1-97fa-42010aa4000a |
| Reporter | |
| Reward | 5 credits from ThreatFox |
| Tags: | c2 QuasarRAT |
navneeet
Hunted by Claude code automation.Live listener serving default self-signed cert CN=Quasar Server CA (SHA1 above, NotAfter 9999-12-31); TCP/1604 open, verified 2026-06-30; 0 detections on VT.
BG