s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.tscookie

📛 Threat Title

Malware family: TSCookie

Category: TSCookie First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.tscookie`. Printable name: TSCookie.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.tscookie VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.tscookie

IOC database

Type
domain
Value
elf.tscookie
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.tscookie

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.tscookie

References (1)

Remediations (9)

  • web:attack.mitre.org

    TSCookie is a remote access tool (RAT) that has been used by BlackTech in campaigns against Japanese targets. [1] [2]. TSCookie has been referred to as PLEAD though more recent reporting indicates a separation between the two. [3] [2]

  • web:blogs.jpcert.or.jp

    Previously, we explained about malware " TSCookie " and "PLEAD" which are used by an attack group BlackTech. Their activities have been continuously observed in Japan as of now. We have been seeing that a new malware variant is being used after...

  • web:cve.nohackme.com

    TSCookie is a remote access tool (RAT) that has been used by BlackTech in campaigns against Japanese targets.. TSCookie has been referred to as PLEAD though more recent reporting indicates a separation between the two.

  • web:cyber-kill-chain.ch

    TSCookie is a remote access tool (RAT) that has been used by BlackTech in campaigns against Japanese targets. [1] [2]. TSCookie has been referred to as PLEAD though more recent reporting indicates a separation between the two. [3] [2]

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the TSCookie malware family including references, samples and yara signatures.

  • web:misp-galaxy.org

    TSCookie is a remote access tool (RAT) that has been used by BlackTech in campaigns against Japanese targets. (Citation: JPCert TSCookie March 2018) (Citation: JPCert BlackTech Malware September 2019). TSCookie has been referred to as PLEAD though more recent reporting indicates a separation between the two.

  • web:soc.cyber.wa.gov.au

    The actors have used a range of custom malware families targeting Windows®, Linux®, and FreeBSD® operating systems. Custom malware families employed by BlackTech include: BendyBear [S0574] Bifrose BTSDoor FakeDead (a.k.a. TSCookie ) [S0436] Flagpro [S0696] FrontShell (FakeDead's downloader module) IconDown PLEAD [S0435] SpiderPig SpiderSpring ...

  • web:support.trellix.com

    The BlackTech threat actor has been in operation since at least 2012 and are known to target government agencies and private organizations with multiple malware families including PLEAD and TSCookie . In early 2020 it was discovered the cyber espionage group is also responsible for a variant of TSCookie targeted at the Linux operating system.

  • web:www.picussecurity.com

    TSCookie is used by adversaries for credential theft, data exfiltration, and deploying additional malware . BlackTech APT group uses FrontShell as a downloader for FakeDead. FlagPro FlagPro is a first-stage downloader designed to infiltrate and compromise Windows systems.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.