s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-py.masepie

📛 Threat Title

Malware family: MASEPIE

Category: MASEPIE First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `py.masepie`. Printable name: MASEPIE.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain py.masepie VT: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/py.masepie (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))

IOC database

Type
domain
Value
py.masepie
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-py.masepie

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/py.masepie (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))

References (1)

Remediations (10)

  • web:bazaar.abuse.ch

    Malware samples associated with tag MasePie MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with MasePie . Database Entry

  • web:dailysecurityreview.com

    To establish persistence on the infected device, MASEPIE modifies the Windows Registry and adds a LNK file with a deceptive name ('SystemUpdate.lnk') to the Windows Startup folder. According to CERT-UA#8399 alert, the malware's primary role is to download additional malware on the infected device and steal data.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the MASEPIE malware family including references, samples and yara signatures.

  • web:media.defense.gov

    MASEPIE Malware In December 2023, APT28 actors wrote MASEPIE[6], a small Python backdoor capable of executing arbitrary commands on victim machines. An FBI investigation revealed that on more than one occasion, APT28 used compromised Ubiquiti EdgeRouters as command-and-control infrastructure for MASEPIE backdoors deployed against targets.

  • web:socprime.com

    MASEPIE from the group's adversary toolkit is a Python-based malware with core capabilities designed for file transfer and command execution using TCP protocol. Data is encrypted via the AES-128-CBC algorithm.

  • web:threatintelligence.garden.handsomezebra.com

    MASEPIE Description (BleepingComputer) The links redirect victims to malicious web resources that employ JavaScript to drop a Windows shortcut file (LNK) that launches PowerShell commands to trigger an infection chain for a new Python malware downloader called 'MASEPIE.' MASEPIE establishes persiste...

  • web:www.bleepingcomputer.com

    Ukraine's Computer Emergency Response Team (CERT) is warning of a new phishing campaign that allowed Russia-linked hackers to deploy previously unseen malware on a network in under one hour.

  • web:www.broadcom.com

    The links redirect victims to malicious web resources that employ JavaScript to drop a Windows shortcut file (LNK) that launches PowerShell commands to trigger an infection chain for a new Python malware downloader called 'MASEPIE.' The malware's primary role is to download additional malware on the infected device and steal data.

  • web:www.cisa.gov

    MASEPIE [8] While other malware variants, such as OCEANMAP and STEELHOOK, [8] were not directly observed targeting logistics or IT entities, their deployment against victims in other sectors in Ukraine and other Western countries suggest that they could be deployed against logistics and IT entities should the need arise.

  • web:www.redpacketsecurity.com

    Ukraine's Computer Emergency Response Team (CERT) is warning of a new phishing campaign that allowed Russia-linked hackers to deploy previously unseen malware on a network in under one hour. APT28, aka Fancy Bear or Strontium, is a Russian state-sponsored threat actor known for targeting government entities, businesses, universities, research institutes, and think tanks in Western countries ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.