s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.powerstats

📛 Threat Title

Malware family: POWERSTATS

Category: POWERSTATS First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.powerstats`. Printable name: POWERSTATS. Aliases: Valyria.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain ps1.powerstats VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ps1.powerstats

IOC database

Type
domain
Value
ps1.powerstats
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-ps1.powerstats

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ps1.powerstats

References (1)

Remediations (10)

  • web:attack.mitre.org

    POWERSTATS POWERSTATS is a PowerShell-based first stage backdoor used by MuddyWater. [1]

  • web:documents.trendmicro.com

    Apart from discovering new campaigns related to MuddyWater, we also uncovered crucial information related to the group's old and recent activities. These include findings on the threat actor group's connection to some Android malware variants, its use of false flags to misattribute campaigns to certain countries, its infrastructure, and its target countries and industries. We will also ...

  • web:en.wikipedia.org

    MuddyWater is an Iranian cyberespionage and advanced persistent threat (APT) group that is widely considered to be part of, or subordinate to, the Iranian Ministry of Intelligence and Security (MOIS). [1][2] First publicly identified in 2017, it has targeted government agencies, telecommunications operators, defense organizations, universities, oil and gas companies, across the Middle East ...

  • web:malpedia.caad.fkie.fraunhofer.de

    POWERSTATS is a backdoor written in powershell. It has the ability to disable Microsoft Office Protected View, fingerprint the victim and receive commands.

  • web:radar.certfa.com

    The research team at Palo Alto Networks has discovered a group of targeted cyber-attacks against the Middle East region that occurred between February and October 2017, carried out by "MuddyWater". These attacks are espionage-related. The group used a PowerShell-based first-stage backdoor called " POWERSTATS ", which evolved slowly over time, and targeted countries including the USA and India ...

  • web:www.bleepingcomputer.com

    US and UK cybersecurity and law enforcement agencies today shared info on new malware deployed by the Iranian-backed MuddyWatter hacking group in attacks targeting critical infrastructure worldwide.

  • web:www.cisa.gov

    This advisory provides observed tactics, techniques, and procedures (TTPs); malware ; and indicators of compromise (IOCs) associated with this Iranian government-sponsored APT activity to aid organizations in the identification of malicious activity against sensitive networks.

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

  • web:www.picussecurity.com

    This blog breaks down the newly observed MuddyWater malware families in detail. Test your security controls against MuddyWater Attacks MuddyWater Cyber-Espionage Group MuddyWater is a cyber-espionage group that targets various organizations in telecommunications, defense, local government, oil, and natural gas sectors worldwide.

  • web:www.securityweek.com

    As part of the campaign delivering the LaZagne credential dumper, the attackers patched the malware to drop and run POWERSTATS in the main function. "While MuddyWater appears to have no access to zero-days and advanced malware variants, it still managed to compromise its targets. This can be attributed to the constant development of their ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.