TF-MAL-py.masepie
📛 Threat Title
Malware family: MASEPIE
Description
ThreatFox malware family `py.masepie`. Printable name: MASEPIE.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
py.masepie
VT: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/py.masepie (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))
IOC database
- Type
- domain
- Value
py.masepie- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-py.masepie
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/py.masepie (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:bazaar.abuse.ch
Malware samples associated with tag MasePie MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with MasePie . Database Entry
-
web:dailysecurityreview.com
To establish persistence on the infected device, MASEPIE modifies the Windows Registry and adds a LNK file with a deceptive name ('SystemUpdate.lnk') to the Windows Startup folder. According to CERT-UA#8399 alert, the malware's primary role is to download additional malware on the infected device and steal data.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the MASEPIE malware family including references, samples and yara signatures.
-
web:media.defense.gov
MASEPIE Malware In December 2023, APT28 actors wrote MASEPIE[6], a small Python backdoor capable of executing arbitrary commands on victim machines. An FBI investigation revealed that on more than one occasion, APT28 used compromised Ubiquiti EdgeRouters as command-and-control infrastructure for MASEPIE backdoors deployed against targets.
-
web:socprime.com
MASEPIE from the group's adversary toolkit is a Python-based malware with core capabilities designed for file transfer and command execution using TCP protocol. Data is encrypted via the AES-128-CBC algorithm.
-
web:threatintelligence.garden.handsomezebra.com
MASEPIE Description (BleepingComputer) The links redirect victims to malicious web resources that employ JavaScript to drop a Windows shortcut file (LNK) that launches PowerShell commands to trigger an infection chain for a new Python malware downloader called 'MASEPIE.' MASEPIE establishes persiste...
-
web:www.bleepingcomputer.com
Ukraine's Computer Emergency Response Team (CERT) is warning of a new phishing campaign that allowed Russia-linked hackers to deploy previously unseen malware on a network in under one hour.
-
web:www.broadcom.com
The links redirect victims to malicious web resources that employ JavaScript to drop a Windows shortcut file (LNK) that launches PowerShell commands to trigger an infection chain for a new Python malware downloader called 'MASEPIE.' The malware's primary role is to download additional malware on the infected device and steal data.
-
web:www.cisa.gov
MASEPIE [8] While other malware variants, such as OCEANMAP and STEELHOOK, [8] were not directly observed targeting logistics or IT entities, their deployment against victims in other sectors in Ukraine and other Western countries suggest that they could be deployed against logistics and IT entities should the need arise.
-
web:www.redpacketsecurity.com
Ukraine's Computer Emergency Response Team (CERT) is warning of a new phishing campaign that allowed Russia-linked hackers to deploy previously unseen malware on a network in under one hour. APT28, aka Fancy Bear or Strontium, is a Russian state-sponsored threat actor known for targeting government entities, businesses, universities, research institutes, and think tanks in Western countries ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.