> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# IOC Alert: Quasar RAT Command-and-Control Domain via Ngrok Tunnel
- URL: https://darkwebinformer.com/ioc-alert-quasar-rat-command-and-control-domain-via-ngrok-tunnel/
- Published: 2025-10-28T21:32:57.000Z
- Updated: 2025-10-28T21:38:47.000Z
- Author: Dark Web Informer
- Tags: IOC

## 📖 Overview

A command-and-control (C2) endpoint leveraging **Ngrok tunneling infrastructure** has been identified in association with **Quasar RAT** operations. The domain `10.tcp.eu.ngrok.io` was observed resolving to an AWS-hosted IP address. While the Ngrok tunnel is currently inactive and displays an error page, this infrastructure is often used by threat actors for temporary or disposable C2 endpoints. Confidence is assessed at 100%.

---

## 📌 Key Details

| Field           | Information                                                |
| --------------- | ---------------------------------------------------------- |
| **Type**        | Domain                                                     |
| **Indicator**   | 10.tcp.eu.ngrok\[.\]io                                     |
| **Threat Type** | Botnet C2                                                  |
| **Malware**     | win.quasar\_rat                                            |
| **Confidence**  | 100%                                                       |
| **Date**        | 28 Oct 2025 – 18:01:15 UTC                                 |
| **Tags**        | c2, domain, quasar, RAT, triage                            |
| **Reporter**    | DonPasci                                                   |
| **Reference**   | [Triage Sandbox Report](https://tria.ge/251028-t3sf4saj81) |

---

## 🔎 URLScan Result

- **Verdict Score:** 0
- **Page Title:** ERR\_NGROK\_3200 – Tunnel 10.tcp.eu.ngrok.io not found
- **Screenshot:** [View Screenshot](https://urlscan.io/screenshots/48351bb8-29e6-4969-a12c-6227c9113d15.png)
- **Result:** [Full Scan Report](https://urlscan.io/result/48351bb8-29e6-4969-a12c-6227c9113d15/)

![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2025/10/97623597862359876293875698723-2.jpg)

---

## 📡 Domain & Certificate Info

- **DNS A Record:** 18\[.\]195\[.\]122\[.\]13

---

## 📡 Related Intelligence

- **Certificate Transparency:** [crt.sh Report](https://crt.sh/?q=10.tcp.eu.ngrok.io)
- **VirusTotal Report:** [VirusTotal Domain Report](https://www.virustotal.com/gui/domain/10.tcp.eu.ngrok.io)
- **URLScan Domain Overview:** [urlscan.io Domain Page](https://urlscan.io/domain/10.tcp.eu.ngrok.io)
- **DNS Analytics:** [dnslytics.com Report](https://dnslytics.com/domain/10.tcp.eu.ngrok.io)

---

## 🛡️ Defensive Guidance

- Block **10.tcp.eu.ngrok\[.\]io** and related **Ngrok subdomains** in perimeter and endpoint security policies.
- Monitor for **Quasar RAT indicators**, such as outbound TCP connections to Ngrok tunnels or unusual persistence activity (registry edits, WMI subscriptions).
- Detect and block **Ngrok tunnels** used in non-development environments to prevent misuse for covert remote access.
- Audit outbound connections to **AWS IP ranges** hosting transient C2 endpoints.

---

⚠️ This IOC highlights the **increasing abuse of Ngrok tunneling services** by remote access trojans like Quasar RAT, enabling threat actors to establish short-lived, encrypted C2 channels that easily bypass traditional perimeter defenses.