s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.flexnet

📛 Threat Title

Malware family: FlexNet

Category: FlexNet First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.flexnet`. Printable name: FlexNet. Aliases: gugi.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.flexnet VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.flexnet

IOC database

Type
domain
Value
apk.flexnet
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.flexnet

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.flexnet

References (1)

Remediations (10)

  • web:app.opencve.io

    Explore the latest vulnerabilities and security issues of Flexera in the CVE database

  • web:community.flexera.com

    Virus and malware scanning in line with your normal organizational standards and procedures should be performed on all computers that have FlexNet Manager Suite components installed. No exclusions related to FlexNet Manager Suite generally need to be configured. Consider the following points if a scanning tool raises an alert in relation to files in a FlexNet Manager Suite component as being ...

  • web:community.revenera.com

    An elevated privilege vulnerability was discovered in the FlexNet Publisher License Server. This article provides details about the vulnerability as well as mitigation and remediation options.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the FlexNet malware family including references, samples and yara signatures.

  • web:support.safe.com

    Safe Software is aware of the vulnerability known as CVE-2024-2658 impacting FlexNet Publisher. This article provides an overview of our analysis of this vulnerability and our mitigation advice for users.

  • web:www.autodesk.com

    The Flexnet Publisher version (located in "C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe") comes with the latest Autodesk product and is outdated (11.16..0). Possibly vulnerable to CVE-2018-20034 remediated in FlexNet Publisher - Community (flexera.com) and CVE-2018-20033 remediated in FlexNet Publisher. The lmgrd and vendor daemon components ...

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.crowdstrike.com

    CrowdStrike discovered a vulnerability in Flexera's FlexNet Inventory Agent that can be exploited to allow arbitrary code execution and privilege escalation under certain conditions. The vulnerability was disclosed to Flexera and is tracked under CVE-2023-29082. The mitigation was included in the 19.4.0 version of the agent that was released by Flexera in April 2023. The advisory was published ...

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

  • web:www.wiz.io

    CVE-2024-2658: FlexNet Publisher vulnerability analysis and mitigation Overview A misconfiguration vulnerability has been identified in FlexNet Publisher versions prior to 2024 R1 (11.19.6.0), specifically in the lmadmin.exe component.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.