s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.cookbox

📛 Threat Title

Malware family: COOKBOX

Category: COOKBOX First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.cookbox`. Printable name: COOKBOX.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain ps1.cookbox VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ps1.cookbox

IOC database

Type
domain
Value
ps1.cookbox
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-ps1.cookbox

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ps1.cookbox

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    Upon execution, the malware facilitated persistent control over infected devices, posing a significant threat to targeted individuals. One's timely detection and mitigation actions disrupted FlyingYeti's operations at various stages, compelling the threat actor to continually adapt their tactics.

  • web:blog.cloudflare.com

    If opened, the files would result in infection with the PowerShell malware known as COOKBOX , allowing FlyingYeti to support follow-on objectives, such as installation of additional payloads and control over the victim's system.

  • web:itsecuritynewsbox.com

    Russia-linked threat actor FlyingYeti is targeting Ukraine with a phishing campaign to deliver the PowerShell malware COOKBOX . Cloudflare researchers discovered phishing campaign conducted by a Russia-linked threat actor FlyingYeti (aka UAC-0149) targeting Ukraine. The experts published a report to describe real-time effort to disrupt and delay this threat activity.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to CERT-UA, COOKBOX is a PowerShell script that implements the functionality of downloading and executing PowerShell cmdlets. For each affected computer, a unique identifier is calculated using cryptographic transformations (SHA256/MD5 hash functions) based on a combination of computer name and disk serial number, which is transmitted in the "X-Cookie" header of HTTP requests ...

  • web:marketingable.mphasis.com

    "The malware is designed to persist on a host, serving as a foothold in the infected device. Once installed, this variant of COOKBOX will make requests to the DDNS domain postdock[.]serveftp[.]com for C2, awaiting PowerShell cmdlets that the malware will subsequently run," Cloudflare said.

  • web:socprime.com

    Detect the UAC-0149 targeted attack against Ukraine using COOKBOX malware with curated detection algorithms from SOC Prime Platform.

  • web:thehackernews.com

    The RAR file, once launched, weaponizes CVE-2023-38831 to execute the COOKBOX malware . "The malware is designed to persist on a host, serving as a foothold in the infected device.

  • web:www.admirationnews.com

    Russia-linked threat actor FlyingYeti is targeting Ukraine with a phishing campaign to deliver the PowerShell malware COOKBOX .Cloudflare researchers discovered phishing campaign conducted by a Russia-linked threat actor FlyingYeti (aka UAC-0149) targeting Ukraine. The experts published a report to describe real-time effort to disrupt and delay this threat activity. At the beginning of Russia ...

  • web:www.anavem.com

    KB890830 delivers the March 2026 update for Windows Malicious Software Removal Tool (MSRT), adding detection and removal capabilities for 47 new malware families including advanced ransomware variants and AI-powered threats targeting Windows 10, Windows 11, and Windows Server systems.

  • web:www.linkedin.com

    "If opened, the files would result in infection with the PowerShell malware known as COOKBOX , allowing FlyingYeti to support follow-on objectives, such as installation of additional payloads and ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.