s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.offode

📛 Threat Title

Malware family: OFFODE

Category: OFFODE First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.offode`. Printable name: OFFODE.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain js.offode VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.offode

IOC database

Type
domain
Value
js.offode
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-js.offode

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.offode

References (1)

Remediations (10)

  • web:blog.cytidel.com

    Remediation Microsoft has already implemented an interim mitigation via Feature Flighting, which is automatically enabled across all supported versions of Office and Microsoft 365. Ensure that this mitigation is active on all affected systems to provide temporary protection until the official patch is released.

  • web:blog.gridinsoft.com

    Microsoft says its malware and unwanted software names follow the CARO naming scheme. In a typical Defender name, the part before the colon is the type, the part after the colon is the platform, the part after the slash is the family , and a suffix beginning with ! is an internal Microsoft indicator.

  • web:github.com

    Remediate malicious email delivered in Office 365 [!INCLUDE MDO Trial banner] Remediation means to take a prescribed action against a threat.

  • web:jeffreyappel.nl

    In Defender for Office Automated Investigation and Response (AIR) is important. Microsoft has improved the features surrounding Auto- Remediation of Malicious Messages in the Automated Investigation and Response (AIR) capability over the past months, aiming to avoid manual actions when malicious content is detected.

  • web:knowledge.broadcom.com

    Configuration The Auto Remediation Settings tab is located in the ClientNet portal under: Dashboard > Services >Email Threat Detection and Response > Auto Remediation Settings You must first set up your Microsoft Office 365 service to work correctly with Auto Remediation . Click the Manage Tenants option to set up permissions to allow Auto Remediation access to your users' inboxes. The ...

  • web:learn.microsoft.com

    Learn about automated remediation in automated investigation and response (AIR) in Microsoft Defender for Office 365 Plan 2.

  • web:www.breachsense.com

    Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.modernsecurity.nl

    Enable Defender for Office 365 Auto‑Remediation to cut SOC dwell time and auto-delete threats. Learn how it works and how to monitor it.

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.