TF-MAL-ps1.powerstats
📛 Threat Title
Malware family: POWERSTATS
Description
ThreatFox malware family `ps1.powerstats`. Printable name: POWERSTATS. Aliases: Valyria.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
ps1.powerstats
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ps1.powerstats
IOC database
- Type
- domain
- Value
ps1.powerstats- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-ps1.powerstats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ps1.powerstats
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
POWERSTATS POWERSTATS is a PowerShell-based first stage backdoor used by MuddyWater. [1]
-
web:documents.trendmicro.com
Apart from discovering new campaigns related to MuddyWater, we also uncovered crucial information related to the group's old and recent activities. These include findings on the threat actor group's connection to some Android malware variants, its use of false flags to misattribute campaigns to certain countries, its infrastructure, and its target countries and industries. We will also ...
-
web:en.wikipedia.org
MuddyWater is an Iranian cyberespionage and advanced persistent threat (APT) group that is widely considered to be part of, or subordinate to, the Iranian Ministry of Intelligence and Security (MOIS). [1][2] First publicly identified in 2017, it has targeted government agencies, telecommunications operators, defense organizations, universities, oil and gas companies, across the Middle East ...
-
web:malpedia.caad.fkie.fraunhofer.de
POWERSTATS is a backdoor written in powershell. It has the ability to disable Microsoft Office Protected View, fingerprint the victim and receive commands.
-
web:radar.certfa.com
The research team at Palo Alto Networks has discovered a group of targeted cyber-attacks against the Middle East region that occurred between February and October 2017, carried out by "MuddyWater". These attacks are espionage-related. The group used a PowerShell-based first-stage backdoor called " POWERSTATS ", which evolved slowly over time, and targeted countries including the USA and India ...
-
web:www.bleepingcomputer.com
US and UK cybersecurity and law enforcement agencies today shared info on new malware deployed by the Iranian-backed MuddyWatter hacking group in attacks targeting critical infrastructure worldwide.
-
web:www.cisa.gov
This advisory provides observed tactics, techniques, and procedures (TTPs); malware ; and indicators of compromise (IOCs) associated with this Iranian government-sponsored APT activity to aid organizations in the identification of malicious activity against sensitive networks.
-
web:www.ncsc.gov.uk
How to defend organisations against malware or ransomware attacks.
-
web:www.picussecurity.com
This blog breaks down the newly observed MuddyWater malware families in detail. Test your security controls against MuddyWater Attacks MuddyWater Cyber-Espionage Group MuddyWater is a cyber-espionage group that targets various organizations in telecommunications, defense, local government, oil, and natural gas sectors worldwide.
-
web:www.securityweek.com
As part of the campaign delivering the LaZagne credential dumper, the attackers patched the malware to drop and run POWERSTATS in the main function. "While MuddyWater appears to have no access to zero-days and advanced malware variants, it still managed to compromise its targets. This can be attributed to the constant development of their ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.