TF-MAL-py.anubisbackdoor
📛 Threat Title
Malware family: Anubis Backdoor
Description
ThreatFox malware family `py.anubisbackdoor`. Printable name: Anubis Backdoor.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
py.anubisbackdoor
VT: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/py.anubisbackdoor (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))
IOC database
- Type
- domain
- Value
py.anubisbackdoor- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-py.anubisbackdoor
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/py.anubisbackdoor (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cyberpress.org
Mitigation and Response Given the Anubis Backdoor's ability to evade detection, proactive measures are essential for preventing its spread. Organizations should ensure that their security systems are updated with the latest threat intelligence, including the IOCs associated with this malware .
-
web:cybersecuritynews.com
A newly discovered Python-based backdoor called AnubisBackdoor is enabling threat actors to execute remote commands on compromised systems while completely evading detection by most antivirus solutions. Developed by the notorious threat group Savage Ladybug (also known as FIN7), this malware combines simplicity with effectiveness through mild obfuscation techniques, allowing attackers to ...
-
web:dailysecurityreview.com
Anubis ransomware combines encryption and file-wiping capabilities, targeting Windows, Linux, and NAS systems with stealthy command-line execution and affiliate-driven campaigns across multiple industries.
-
web:fieldeffect.com
Despite law enforcement disruptions—including arrests of key members—FIN7 has continued to operate, adapting its tactics and expanding its malware arsenal. FIN7's Anubis backdoor highlights the threat actor's ongoing efforts to develop stealthy and adaptable malware .
-
web:malpedia.caad.fkie.fraunhofer.de
Anubis Backdoor Propose Change Actor (s): FIN7 According to Prodaft, this is a Python-based backdoor used by the Savage Ladybug (FIN7) group is developed to provide remote access, execute commands, and steal data. It is obfuscated to avoid detection.
-
web:rewterz.com
The malware's core function is executing system commands via the shell, using Python's subprocess module. This lets attackers control infected machines remotely, making detection and mitigation challenging.
-
web:securitricks.com
Description FIN7, a notorious cybercrime group, has developed a new Python -based backdoor called AnubisBackdoor. This sophisticated tool employs multi-stage attacks, encryption, and obfuscation techniques to evade detection. The malware is distributed through phishing campaigns and uses AES encryption with multiple layers of obfuscation. AnubisBackdoor 's core functionality includes network ...
-
web:thehackernews.com
The financially motivated threat actor known as FIN7 has been linked to a Python-based backdoor called Anubis (not to be confused with an Android banking trojan of the same name) that can grant them remote access to compromised Windows systems. "This malware allows attackers to execute remote shell ...
-
web:www.pcrisk.com
Anubis malware overview Anubis is a backdoor - it is designed to prep systems for further infection and carry it out. Like most malicious programs within this classification, Anubis was created with an emphasis on stealth. It has multiple anti-detection and anti-analysis capabilities. This malware has multi-layered obfuscation.
-
web:www.secureblink.com
FIN7's Anubis Backdoor hijacks Windows systems via compromised SharePoint sites. Learn how this Python-based threat operates and how to defend your enterprise.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.