s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.mazarbot

📛 Threat Title

Malware family: MazarBot

Category: MazarBot First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.mazarbot`. Printable name: MazarBot.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.mazarbot VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.mazarbot

IOC database

Type
domain
Value
apk.mazarbot
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.mazarbot

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.mazarbot

References (1)

Remediations (10)

  • web:androidexperto.com

    Newly reported UEFI vulnerabilities in Gigabyte motherboards have raised serious concerns because they can undermine one of the PC's most trusted startup defenses: Secure Boot. If exploited, these flaws could allow an attacker to execute unauthorized code during the boot process, potentially clearing the way for firmware-level implants that load before the operating system and evade many ...

  • web:attack.mitre.org

    MazarBOT MazarBOT is Android malware that was distributed via SMS in Denmark in 2016. [1]

  • web:bazaar.abuse.ch

    Malware samples associated with tag MazarBot MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with MazarBot . Database Entry

  • web:github.com

    MBC content in markdown. Contribute to MBCProject/mbc-markdown development by creating an account on GitHub.

  • web:heimdalsecurity.com

    If this Android malware takes control over your phone, expect the worst. Read about Mazar BOT and how you can protect your phone and data:

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the MazarBot malware family including references, samples and yara signatures.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.ic3.gov

    Overview Threat actors are deploying ATM jackpotting malware , including the Ploutus family malware , to infect ATMs and force them to dispense cash. Ploutus malware exploits the eXtensions for Financial Services (XFS), the layer of software that instructs an ATM what to physically do. When a legitimate transaction occurs, the ATM application sends instructions through XFS for bank authorization ...

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.ncsc.gov.uk

    This guidance helps private and public sector organisations deal with the effects of malware (which includes ransomware). It provides actions to help organisations prevent a malware infection, and also steps to take if you're already infected. Following this guidance will reduce: the likelihood of becoming infected the spread of malware throughout your organisation the impact of the infection

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.