s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.ghostweaver

📛 Threat Title

Malware family: GhostWeaver

Category: GhostWeaver First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.ghostweaver`. Printable name: GhostWeaver.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain ps1.ghostweaver VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ps1.ghostweaver

IOC database

Type
domain
Value
ps1.ghostweaver
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-ps1.ghostweaver

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ps1.ghostweaver

References (1)

Remediations (10)

  • web:clickcontrol.com

    MintsLoader malware is being used to distribute GhostWeaver , a sophisticated PowerShell-based RAT, through multi-stage attacks. Active since early 2023, MintsLoader employs obfuscated JavaScript…

  • web:cybernoz.com

    The malware loader known as MintsLoader has been used to deliver a PowerShell-based remote access trojan called GhostWeaver . "MintsLoader operates through a multi-stage infection chain involving obfuscated JavaScript and PowerShell scripts," Recorded Future's Insikt Group said in a report shared with The Hacker News. "The malware employs sandbox and virtual machine evasion techniques ...

  • web:cybersecuritynews.com

    MintsLoader Attack Chain illustrates how the malware creates multiple persistence points to ensure survival across system reboots and attempts at remediation . A particularly notable feature is its ability to detect and disable endpoint protection products through direct manipulation of Windows Management Instrumentation (WMI) objects. The ClickFix component represents an evolution in social ...

  • web:malpedia.caad.fkie.fraunhofer.de

    According to TRAC Labs, the GhostWeaver backdoor not only maintains continuous, authenticated communication with its command-and-control server but also includes functionalities to generate DGA domains (using a fixed-seed algorithm based on the week number and year), deliver additional payloads via remote commands and bypass certificate validation by leveraging a ...

  • web:securitricks.com

    The article details a sophisticated malware infection chain involving SocGholish, MintsLoader, and the GhostWeaver backdoor. The attack begins with a fake browser update, progressing through multiple stages to deploy a PowerShell backdoor and various plugins.

  • web:securityaffairs.com

    If the target passes the checks, the loader downloads advanced malware like GhostWeaver , a PowerShell-based RAT with TLS-encrypted C2 communication and capabilities to redeploy MintsLoader. If the system fails validation, the C2 may deliver a decoy executable like AsyncRAT, which has led to misclassifications in threat reports.

  • web:techinvestornews.io

    The malware loader known as MintsLoader has been used to deliver a PowerShell-based remote access trojan called GhostWeaver . "MintsLoader operates through a multi-stage infection chain involving obfuscated JavaScript and PowerShell scripts," Recorded Future's Insikt Group said in a report shared with The Hacker News. "The malware employs sandbox and virtual machine evasion techniques, a domain

  • web:thehackernews.com

    The malware loader known as MintsLoader has been used to deliver a PowerShell-based remote access trojan called GhostWeaver . "MintsLoader operates through a multi-stage infection chain involving obfuscated JavaScript and PowerShell scripts," Recorded Future's Insikt Group said in a report shared ...

  • web:www.derp.ca

    A TAG-124 fileless PowerShell RAT with 1/76 VT detection. We decoded the wire protocol, four DGA systems, persistence modes, and probed the live C2 server.

  • web:www.recordedfuture.com

    Discover how MintsLoader operates as a stealthy, obfuscated malware loader distributing GhostWeaver , StealC, and BOINC. Read Recorded Future's in-depth analysis of its evasion tactics, DGA-based C2s, and use in phishing and drive-by campaigns.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.