VenomRAT
2 addresses convicted as VenomRAT remote-access trojan controllers — 2 still listed, 0 archived. Observed from 2026-09-01.
Detection packs
Rules for the 2 still-listed addresses on this page, regenerated as the archive updates; archived episodes are omitted, and a rule can lag a withdrawal by up to five minutes. Suricata rules are rev:2 — alert tcp on address and port, alert tls where a full certificate fingerprint is published — and carry the archive's own episode ids as sids, so packs load beside each other and beside any per-host file. YARA packs are hash matches only: this site holds no file bytes.
About
A commercial fork of AsyncRAT — sold as a product, unlike the open-source DcRat — that shares its lineage's wire protocol and builder certificate template. A listener is listed under this name only where a recovered sample configuration proved the fork; where only the network was observed it sits under DcRat or VenomRAT instead, because from outside the two cannot be told apart. Re-labelled by the upstream in place: 1 host earlier labelled DcRat or VenomRAT; 1 host earlier labelled AsyncRAT. The archive keeps only the most recent earlier label per episode.
Ports
Addresses
Ordered by when this archive first recorded them, newest first — a stable ordering, so a page holds the same addresses tomorrow. Archived addresses are included and marked; they are the majority of this corpus over time.
Listed in error?
These pages are generated from automated scanning and are publicly available. Write to support@publicmosaic.com — see abuse & takedown, or opt-out to exclude a network range from scanning.