public mosaic llc support@publicmosaic.com
malware family

Quasar-family

11 addresses convicted as Quasar-family remote-access trojan controllers — 11 still listed, 0 archived. Observed from 2026-08-28.

TLP:CLEAR
addresses 11 11 still listed
observations 12 address and port pairs
networks 8 distinct ASNs
first seen 2026-08-28 oldest observation

Detection packs

Rules for the 11 still-listed addresses on this page, regenerated as the archive updates; archived episodes are omitted, and a rule can lag a withdrawal by up to five minutes. Suricata rules are rev:2 — alert tcp on address and port, alert tls where a full certificate fingerprint is published — and carry the archive's own episode ids as sids, so packs load beside each other and beside any per-host file. YARA packs are hash matches only: this site holds no file bytes.

About

Convicted on a certificate structure the Quasar codebase and its forks share, rather than on any name in the certificate. Every listener recorded here carried a subject name that was NOT Quasar's default — some another product's, some a random string — which is exactly why the structure is what convicted them. Read it as "built on this codebase", not as "running Quasar": most of what this structure matches is a derivative rather than Quasar itself. Where the default name did survive, the listener is recorded at /c2/quasar-rat instead, the stronger claim of the two. The same address can appear on both, because a label describes a listener and a machine can run more than one. Re-labelled by the upstream in place: 2 hosts earlier labelled DcRat or VenomRAT; 1 host earlier labelled DcRat. The archive keeps only the most recent earlier label per episode.

Ports

:44492:78782:560012:4431:13141:18181:47821:88481

Addresses

Ordered by when this archive first recorded them, newest first — a stable ordering, so a page holds the same addresses tomorrow. Archived addresses are included and marked; they are the majority of this corpus over time.