80.76.49.162
Classification: Suspicious
80.76.49.162 is a suspicious IP address. Linked to Quasarrat malware. Reported by 3 threat sources, last seen 2026-03-15.
MITRE ATT&CK associations
Malware families: QUASARRAT (S0262)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Suspicious Host | AbuseIPDB | 2026-02-22 08:39:14 | 2026-03-15 23:00:06 | anomalous-activity | |
| Quasar RAT | ThreatFox Abuse.ch | 2025-04-14 10:21:16 | 2025-04-16 08:23:23 | malicious-activity | S0262 QuasarRAT |
| AsyncRAT | ThreatFox Abuse.ch | 2024-05-28 13:18:37 | 2024-05-30 12:20:38 | malicious-activity | |
| Malware Download | URLhaus Abuse.ch | 2024-05-28 12:21:50 | 2024-05-28 12:21:58 | malicious-activity |
Tags
asyncrat malware trojan celestybinder port:4545 14april2025 iocbottest port:1000 cinarat quasarrat yggdrasilWhois information
- AS name
- AS399486 Virtuo Networks France
- AS registry
- ripencc
- AS date
- 2018-10-04 00:00:00
- AS CIDR
- 80.76.49.0/24
- Registrant
- Virtuo Networks France
- City
- Secaucus
- State
- NJ
- Postal code
- 07094
- Country
- US — United States 🇺🇸
- First indexed
- 2024-05-28 12:21:50
- Last updated
- 2026-03-16 01:23:21