TF-MAL-ps1.cookbox
📛 Threat Title
Malware family: COOKBOX
Description
ThreatFox malware family `ps1.cookbox`. Printable name: COOKBOX.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
ps1.cookbox
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ps1.cookbox
IOC database
- Type
- domain
- Value
ps1.cookbox- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-ps1.cookbox
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ps1.cookbox
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
Upon execution, the malware facilitated persistent control over infected devices, posing a significant threat to targeted individuals. One's timely detection and mitigation actions disrupted FlyingYeti's operations at various stages, compelling the threat actor to continually adapt their tactics.
-
web:blog.cloudflare.com
If opened, the files would result in infection with the PowerShell malware known as COOKBOX , allowing FlyingYeti to support follow-on objectives, such as installation of additional payloads and control over the victim's system.
-
web:itsecuritynewsbox.com
Russia-linked threat actor FlyingYeti is targeting Ukraine with a phishing campaign to deliver the PowerShell malware COOKBOX . Cloudflare researchers discovered phishing campaign conducted by a Russia-linked threat actor FlyingYeti (aka UAC-0149) targeting Ukraine. The experts published a report to describe real-time effort to disrupt and delay this threat activity.
-
web:malpedia.caad.fkie.fraunhofer.de
According to CERT-UA, COOKBOX is a PowerShell script that implements the functionality of downloading and executing PowerShell cmdlets. For each affected computer, a unique identifier is calculated using cryptographic transformations (SHA256/MD5 hash functions) based on a combination of computer name and disk serial number, which is transmitted in the "X-Cookie" header of HTTP requests ...
-
web:marketingable.mphasis.com
"The malware is designed to persist on a host, serving as a foothold in the infected device. Once installed, this variant of COOKBOX will make requests to the DDNS domain postdock[.]serveftp[.]com for C2, awaiting PowerShell cmdlets that the malware will subsequently run," Cloudflare said.
-
web:socprime.com
Detect the UAC-0149 targeted attack against Ukraine using COOKBOX malware with curated detection algorithms from SOC Prime Platform.
-
web:thehackernews.com
The RAR file, once launched, weaponizes CVE-2023-38831 to execute the COOKBOX malware . "The malware is designed to persist on a host, serving as a foothold in the infected device.
-
web:www.admirationnews.com
Russia-linked threat actor FlyingYeti is targeting Ukraine with a phishing campaign to deliver the PowerShell malware COOKBOX .Cloudflare researchers discovered phishing campaign conducted by a Russia-linked threat actor FlyingYeti (aka UAC-0149) targeting Ukraine. The experts published a report to describe real-time effort to disrupt and delay this threat activity. At the beginning of Russia ...
-
web:www.anavem.com
KB890830 delivers the March 2026 update for Windows Malicious Software Removal Tool (MSRT), adding detection and removal capabilities for 47 new malware families including advanced ransomware variants and AI-powered threats targeting Windows 10, Windows 11, and Windows Server systems.
-
web:www.linkedin.com
"If opened, the files would result in infection with the PowerShell malware known as COOKBOX , allowing FlyingYeti to support follow-on objectives, such as installation of additional payloads and ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.