s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-py.blankgrabber

📛 Threat Title

Malware family: BlankGrabber

Category: BlankGrabber First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `py.blankgrabber`. Printable name: BlankGrabber.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain py.blankgrabber VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/py.blankgrabber

IOC database

Type
domain
Value
py.blankgrabber
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-py.blankgrabber

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/py.blankgrabber

References (1)

Remediations (10)

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as BlankGrabber .

  • web:cyberpress.org

    BlankGrabber's operators are experimenting with a stealthy loader chain that abuses Windows certificate tooling to hide a Rust‑based stager.

  • web:cybersecuritynews.com

    A Python-based information stealer known as BlankGrabber has been caught using a deceptive certificate loader trick to hide a multi-stage malware delivery chain. First identified in 2023, this threat has grown more complex over time and keeps targeting everyday users through widely used online platforms.

  • web:cyberwebspider.com

    BlankGrabber Stealer Exploits Fake Certificates for Malware Delivery The BlankGrabber information stealer, a Python-based threat, has been leveraging deceptive certificate loaders to mask its complex malware delivery process.

  • web:gbhackers.com

    BlankGrabber's operators are now abusing a fake "certificate" loader to hide a multi‑stage Rust and Python infection chain, making this commodity stealer significantly harder.

  • web:malpedia.caad.fkie.fraunhofer.de

    2025-02-15 ⋅ c-b.io ⋅ cyb3rjerry Dissecting a fresh BlankGrabber sample BlankGrabber 2024-10-02 ⋅ ThreatMon ⋅ Aziz Kaplan, ThreatMon, ThreatMon Malware Research Team Amnesia Stealer Technical Malware Analysis Report BlankGrabber 2024-01-02 ⋅ K7 Security ⋅ Sekar P Open Source Stealers (OSS) - Python BlankGrabber 2022-07-05 ⋅ Github (Blank-c) ⋅ Blank-c Github Repository for ...

  • web:malwaretips.com

    Overview: What is Blank Grabber and Why is it Dangerous? Blank Grabber is an information-stealing Trojan - a type of malware that resides in an infected computer and gathers data in order to send it to the attacker. Typical targets are credentials used in online banking services, social media sites, emails, or FTP accounts.

  • web:www.cyfirma.com

    Blank Grabber was being vouched for by an experienced black hat malware developer/reverse engineer, who is a part of the "Stealer Developers" community. The developer of this infostealer has kept the project 'open source', which means that the priority of the operator is developing a reputation in the industry, rather than financial gains.

  • web:www.scworld.com

    Windows systems have been more stealthily compromised by the BlankGrabber malware through the exploitation of a counterfeit certificate holder for multi-stage Rust and Python attack chain concealment, GBHackers News reports.

  • web:www.splunk.com

    Analyze the BlankGrabber Trojan Stealer and learn how to detect its obfuscation, staging, and exfiltration techniques using Splunk security analytics.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.