s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-py.anubisbackdoor

📛 Threat Title

Malware family: Anubis Backdoor

Category: Anubis Backdoor First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `py.anubisbackdoor`. Printable name: Anubis Backdoor.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain py.anubisbackdoor VT: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/py.anubisbackdoor (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))

IOC database

Type
domain
Value
py.anubisbackdoor
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-py.anubisbackdoor

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/py.anubisbackdoor (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))

References (1)

Remediations (10)

  • web:cyberpress.org

    Mitigation and Response Given the Anubis Backdoor's ability to evade detection, proactive measures are essential for preventing its spread. Organizations should ensure that their security systems are updated with the latest threat intelligence, including the IOCs associated with this malware .

  • web:cybersecuritynews.com

    A newly discovered Python-based backdoor called AnubisBackdoor is enabling threat actors to execute remote commands on compromised systems while completely evading detection by most antivirus solutions. Developed by the notorious threat group Savage Ladybug (also known as FIN7), this malware combines simplicity with effectiveness through mild obfuscation techniques, allowing attackers to ...

  • web:dailysecurityreview.com

    Anubis ransomware combines encryption and file-wiping capabilities, targeting Windows, Linux, and NAS systems with stealthy command-line execution and affiliate-driven campaigns across multiple industries.

  • web:fieldeffect.com

    Despite law enforcement disruptions—including arrests of key members—FIN7 has continued to operate, adapting its tactics and expanding its malware arsenal. FIN7's Anubis backdoor highlights the threat actor's ongoing efforts to develop stealthy and adaptable malware .

  • web:malpedia.caad.fkie.fraunhofer.de

    Anubis Backdoor Propose Change Actor (s): FIN7 According to Prodaft, this is a Python-based backdoor used by the Savage Ladybug (FIN7) group is developed to provide remote access, execute commands, and steal data. It is obfuscated to avoid detection.

  • web:rewterz.com

    The malware's core function is executing system commands via the shell, using Python's subprocess module. This lets attackers control infected machines remotely, making detection and mitigation challenging.

  • web:securitricks.com

    Description FIN7, a notorious cybercrime group, has developed a new Python -based backdoor called AnubisBackdoor. This sophisticated tool employs multi-stage attacks, encryption, and obfuscation techniques to evade detection. The malware is distributed through phishing campaigns and uses AES encryption with multiple layers of obfuscation. AnubisBackdoor 's core functionality includes network ...

  • web:thehackernews.com

    The financially motivated threat actor known as FIN7 has been linked to a Python-based backdoor called Anubis (not to be confused with an Android banking trojan of the same name) that can grant them remote access to compromised Windows systems. "This malware allows attackers to execute remote shell ...

  • web:www.pcrisk.com

    Anubis malware overview Anubis is a backdoor - it is designed to prep systems for further infection and carry it out. Like most malicious programs within this classification, Anubis was created with an emphasis on stealth. It has multiple anti-detection and anti-analysis capabilities. This malware has multi-layered obfuscation.

  • web:www.secureblink.com

    FIN7's Anubis Backdoor hijacks Windows systems via compromised SharePoint sites. Learn how this Python-based threat operates and how to defend your enterprise.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.