s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.cactustorch

📛 Threat Title

Malware family: CACTUSTORCH

Category: CACTUSTORCH First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.cactustorch`. Printable name: CACTUSTORCH.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain js.cactustorch VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.cactustorch

IOC database

Type
domain
Value
js.cactustorch
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-js.cactustorch

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.cactustorch

References (1)

Remediations (10)

  • web:apt.etda.or.th

    Home > List all groups > List all tools > List all groups using tool CACTUSTORCH

  • web:bazaar.abuse.ch

    Malware samples associated with tag CactusTorch Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with CactusTorch .

  • web:falconforce.nl

    Burning the CACTUSTORCH Summary: Detect current implementations of DotNetToJS/ CACTUSTORCH by detecting the load of the .NET runtime into an unmanaged process, followed by the creation of a child process or a process injection. Blue: This technique is "bootstrapping an arbitrary .NET assembly and class" from an unmanaged process.

  • web:github.com

    CobaltStrike Load CACTUSTORCH .cna Go to Attack -> Host CACTUSTORCH Payload Fill in fields File hosted and ready to go!

  • web:malpedia.caad.fkie.fraunhofer.de

    CACTUSTORCH Propose Change Actor (s): APT32, Leviathan According to the GitHub repo, CACTUSTORCH is a JavaScript and VBScript shellcode launcher. It will spawn a 32 bit version of the binary specified and inject shellcode into it.

  • web:thehackernews.com

    Microsoft Warns of New CACTUS Ransomware Threat. Malvertising used to deploy DanaBot as initial access. Learn more about this evolving cyber threat.

  • web:www.kroll.com

    For Kroll Responder Customers Kroll's threat intelligence team has created and deployed detection rules for CACTUS. If you have any questions, please contact your technical account manager or submit a support ticket. If you're unsure about your detection capabilities for CACTUS (or any other ransomware variant), get in touch with a Kroll expert today.

  • web:www.mcafee.com

    In corporate environments, attackers use this vector to move laterally through the network. One fileless threat, CactusTorch , uses the DotNetToJScript technique, which loads and executes malicious .NET assemblies straight from memory. These assemblies are the smallest unit of deployment of an application, such as a .dll or .exe.

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.quorumcyber.com

    Malware Operational Overview Cactus is a Ransomware-as-a-Service (RaaS) that has been active since at least March 2023 and has targeted over 200 organisations at time of ICOD. Cactus often attains initial access to target networks by exploiting known vulnerabilities across multiple product lines including, Qlik Sense Enterprise and Ivanti Connect Secure. The malware encrypts itself to protect ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.