TF-MAL-js.cactustorch
📛 Threat Title
Malware family: CACTUSTORCH
Description
ThreatFox malware family `js.cactustorch`. Printable name: CACTUSTORCH.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
js.cactustorch
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.cactustorch
IOC database
- Type
- domain
- Value
js.cactustorch- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-js.cactustorch
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.cactustorch
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:apt.etda.or.th
Home > List all groups > List all tools > List all groups using tool CACTUSTORCH
-
web:bazaar.abuse.ch
Malware samples associated with tag CactusTorch Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with CactusTorch .
-
web:falconforce.nl
Burning the CACTUSTORCH Summary: Detect current implementations of DotNetToJS/ CACTUSTORCH by detecting the load of the .NET runtime into an unmanaged process, followed by the creation of a child process or a process injection. Blue: This technique is "bootstrapping an arbitrary .NET assembly and class" from an unmanaged process.
-
web:github.com
CobaltStrike Load CACTUSTORCH .cna Go to Attack -> Host CACTUSTORCH Payload Fill in fields File hosted and ready to go!
-
web:malpedia.caad.fkie.fraunhofer.de
CACTUSTORCH Propose Change Actor (s): APT32, Leviathan According to the GitHub repo, CACTUSTORCH is a JavaScript and VBScript shellcode launcher. It will spawn a 32 bit version of the binary specified and inject shellcode into it.
-
web:thehackernews.com
Microsoft Warns of New CACTUS Ransomware Threat. Malvertising used to deploy DanaBot as initial access. Learn more about this evolving cyber threat.
-
web:www.kroll.com
For Kroll Responder Customers Kroll's threat intelligence team has created and deployed detection rules for CACTUS. If you have any questions, please contact your technical account manager or submit a support ticket. If you're unsure about your detection capabilities for CACTUS (or any other ransomware variant), get in touch with a Kroll expert today.
-
web:www.mcafee.com
In corporate environments, attackers use this vector to move laterally through the network. One fileless threat, CactusTorch , uses the DotNetToJScript technique, which loads and executes malicious .NET assemblies straight from memory. These assemblies are the smallest unit of deployment of an application, such as a .dll or .exe.
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
-
web:www.quorumcyber.com
Malware Operational Overview Cactus is a Ransomware-as-a-Service (RaaS) that has been active since at least March 2023 and has targeted over 200 organisations at time of ICOD. Cactus often attains initial access to target networks by exploiting known vulnerabilities across multiple product lines including, Qlik Sense Enterprise and Ivanti Connect Secure. The malware encrypts itself to protect ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.