TF-MAL-osx.flashback
📛 Threat Title
Malware family: FlashBack
Description
ThreatFox malware family `osx.flashback`. Printable name: FlashBack. Aliases: FakeFlash.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.flashback
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.flashback
IOC database
- Type
- domain
- Value
osx.flashback- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.flashback
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.flashback
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:learn.microsoft.com
Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.
-
web:support.apple.com
Description: This update runs a malware removal tool that will remove the most common variants of the Flashback malware . If the Flashback malware is found, it presents a dialog notifying the user that malware was removed.
-
web:web-assets.esetstatic.com
The first malware to infect hundreds of thousands of Apple Mac The Apple OS X operating system, like all operating systems, can become a victim of malicious software. Before OSX/ Flashback there had been a few documented cases of malware targeting OS X, but so far OSX/ Flashback has claimed the greatest number of victims. In this article we describe the most interesting technical characteristics ...
-
web:windowsforum.com
The emergence of RESURGE signals more than just another entry in a long line of malware threats. According to CISA, RESURGE contains advanced persistence features inherited from the SPAWNCHIMERA malware family—a group notorious for its ability to survive system reboots and avoid simplistic remediation .
-
web:www.breachsense.com
Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.f-secure.com
Summary Trojan-Downloader:OSX/ Flashback is a family of malicious applications which when installed on a computer will download a payload from a remote site, then modify targeted webpages displayed in the web browser. Variants in the Flashback family may include additional malicious functionalities or characteristics.
-
web:www.huntress.com
Utilize trusted macOS malware removal tools, such as those provided by security vendors, to detect and remove Flashback . Organizations should also deploy endpoint detection and response (EDR) solutions for comprehensive threat mitigation .
-
web:www.ncsc.gov.uk
This guidance helps private and public sector organisations deal with the effects of malware (which includes ransomware). It provides actions to help organisations prevent a malware infection, and also steps to take if you're already infected. Following this guidance will reduce: the likelihood of becoming infected the spread of malware throughout your organisation the impact of the infection
-
web:www.securityweek.com
Flashback Malware - A Detailed History of the Largest Mac OS Malware Outbreak to Date At its peak, the Flashback family of malware infected more than 600,000 Mac users. That number has since fallen dramatically, thanks to the combined efforts of several Anti-Virus firms and scores of malware ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.