s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.starfish

📛 Threat Title

Malware family: StarFish

Category: StarFish First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.starfish`. Printable name: StarFish.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain js.starfish VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.starfish

IOC database

Type
domain
Value
js.starfish
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-js.starfish

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.starfish

References (1)

Remediations (10)

  • web:echoxec.com

    Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...

  • web:malpedia.caad.fkie.fraunhofer.de

    According to IBM X-Force, this is a simple reverse shell. Upon execution, the script generates a unique victim ID by combining the machine's product ID and computer name. It queries a hardcoded server and executes optional commands directly via cmd.exe. Command output is send back using a POST request after completion or a timeout.

  • web:windowsforum.com

    The emergence of RESURGE signals more than just another entry in a long line of malware threats. According to CISA, RESURGE contains advanced persistence features inherited from the SPAWNCHIMERA malware family—a group notorious for its ability to survive system reboots and avoid simplistic remediation .

  • web:www.bitdefender.com

    The malware , dubbed "StilachiRAT," has been spotted in the wild a few times, but researchers have yet to associate it with a threat group. Although threat actors haven't disseminated the RAT on a large scale, researchers decided to disclose details about it, including mitigation steps and indicators of compromise.

  • web:www.breachsense.com

    Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.ibm.com

    Hive0145, the threat actor known for delivering Strela Stealer to exfiltrate email credentials, is back to no good and now targeting Germany using malicious SVG files to download a simple reverse shell X-Force named StarFish .

  • web:www.infoblox.com

    30k sites infected with DNS malware by Detour Dog. Now linked to Strela Stealer, StarFish backdoor, REM Proxy, and Tofsee in global spam campaigns.

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

  • web:www.sentinelone.com

    Play ransomware doesn't play around. See how it compromises networks, demands big payouts, and the best strategies to defend your data.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.