TF-MAL-js.starfish
📛 Threat Title
Malware family: StarFish
Description
ThreatFox malware family `js.starfish`. Printable name: StarFish.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
js.starfish
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.starfish
IOC database
- Type
- domain
- Value
js.starfish- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-js.starfish
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.starfish
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:echoxec.com
Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...
-
web:malpedia.caad.fkie.fraunhofer.de
According to IBM X-Force, this is a simple reverse shell. Upon execution, the script generates a unique victim ID by combining the machine's product ID and computer name. It queries a hardcoded server and executes optional commands directly via cmd.exe. Command output is send back using a POST request after completion or a timeout.
-
web:windowsforum.com
The emergence of RESURGE signals more than just another entry in a long line of malware threats. According to CISA, RESURGE contains advanced persistence features inherited from the SPAWNCHIMERA malware family—a group notorious for its ability to survive system reboots and avoid simplistic remediation .
-
web:www.bitdefender.com
The malware , dubbed "StilachiRAT," has been spotted in the wild a few times, but researchers have yet to associate it with a threat group. Although threat actors haven't disseminated the RAT on a large scale, researchers decided to disclose details about it, including mitigation steps and indicators of compromise.
-
web:www.breachsense.com
Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.ibm.com
Hive0145, the threat actor known for delivering Strela Stealer to exfiltrate email credentials, is back to no good and now targeting Germany using malicious SVG files to download a simple reverse shell X-Force named StarFish .
-
web:www.infoblox.com
30k sites infected with DNS malware by Detour Dog. Now linked to Strela Stealer, StarFish backdoor, REM Proxy, and Tofsee in global spam campaigns.
-
web:www.ncsc.gov.uk
How to defend organisations against malware or ransomware attacks.
-
web:www.sentinelone.com
Play ransomware doesn't play around. See how it compromises networks, demands big payouts, and the best strategies to defend your data.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.