s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-jar.crossrat

📛 Threat Title

Malware family: CrossRAT

Category: CrossRAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `jar.crossrat`. Printable name: CrossRAT. Aliases: Trupto.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain jar.crossrat VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.crossrat

IOC database

Type
domain
Value
jar.crossrat
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-jar.crossrat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.crossrat

References (1)

Remediations (10)

  • web:attack.mitre.org

    Blaich, A., et al. (2018, January 18). Dark Caracal: Cyber-espionage at a Global Scale. Retrieved April 11, 2018.

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as CrossRAT .

  • web:github.com

    CrossRAT is a cross platform malware written in Java, targeting Windows, Linux and MacOS. There are signs that imply that the malware was developed by/for the Dark Caracal APT group.

  • web:macos.checkpoint.com

    CrossRAT is a cross platform malware written in Java, targeting Windows, Linux and MacOS. There are signs that imply that the malware was developed by/for the Dark Caracal APT group.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the CrossRAT malware family including references, samples and yara signatures.

  • web:redcanary.com

    Extended Berkeley Packet Filter (eBPF) is beginning to transform the Linux malware landscape. Here's what defenders should look out for.

  • web:www.fortinet.com

    FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.

  • web:www.jamf.com

    Follow along with Patrick at 40,000ft as he dives deeper into the capabilities of macOS malware first reported by Lookout/EFF in their Dark Caracul analysis.

  • web:www.pcrisk.com

    The internet is full of trojan-type infections that share many similarities. Some examples include Bolik, Ceprolad, and Belonard. Some gather information, whilst others proliferate malware . In any case, infections of this type pose a significant threat to your privacy and computer safety. Therefore, eliminate CrossRAT and other similar infections immediately. How did CrossRAT infiltrate my ...

  • web:www.researchgate.net

    Prevention and detection of eBPF-based malware is also explored, with the goal of providing organizations or legitimate users of eBPF techniques to harden their systems against eBPF-based malware ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.