TF-MAL-osx.pirrit
📛 Threat Title
Malware family: Pirrit
Description
ThreatFox malware family `osx.pirrit`. Printable name: Pirrit.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.pirrit
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.pirrit
IOC database
- Type
- domain
- Value
osx.pirrit- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.pirrit
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.pirrit
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:alden.io
Over the last few years, Apple has put more effort into addressing the growing problem of malware on their platform. One of their primary responses was the introduction of the XProtect suite. This post walks through how to extract a set of encrypted YARA rules stored within the XProtect Remediator binaries and correlate them with their public names. Not including private helper rules, there ...
-
web:intel.dev.threatlabs.protect.jamfcloud.com
Pirrit is a persistent macOS adware first seen in 2016. It emerged again in late 2021 with new activity. Typically installed via malicious DMG files, Pirrit changes browser settings, installs tracking extensions, and configures a local proxy to inject ads. It maintains persistence using a LaunchAgent and hidden user account. With full system control, it could theoretically steal sensitive user ...
-
web:macos.checkpoint.com
Pirrit is an Adware known from Windows since 2014, and a variant for OS X was spotted in 2016. Even though there is no evidence yet of Pirrit taking advantage of it, except pushing pop-up ads by injecting to web pages, it also takes full control over an infected machine and has the ability to steal sensitive information of the user.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Pirrit malware family including references, samples and yara signatures.
-
web:www.cybereason.com
With components such as persistence and the ability to obtain root access, OSX. Pirrit has characteristics usually seen in malware . The catch: OSX. Pirrit didn't execute any harmful functions but the potential to carry out these much more malicious activities was there.
-
web:www.malwarebytes.com
Protection Malwarebytes for Mac detects and removes OSX. Pirrit Remediation Malwarebytes for Mac will detect and remove the components of this malware . Download and install the latest version of Malwarebytes for Mac. Click the "Scan Now" button to perform a system scan. If threats are detected during the scan, a count of detected threats is ...
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
-
web:www.pcrisk.com
Fake Flash updater designed to install adware-type apps that belong to the Pirrit family : Update July 18, 2023 - the Pirrit adware family has undergone significant improvements in its mode of infection and use of anti-analysis techniques. Pirrit uses various lengthy infection chains to infiltrate devices.
-
web:www.threatdown.com
Home remediation Malwarebytes for Mac will detect and remove the components of this malware . Download and install the latest version of Malwarebytes for Mac. Click the "Scan Now" button to perform a system scan. If threats are detected during the scan, a count of detected threats is displayed.
-
web:www.trinitycyber.com
Trinity Cyber recently identified a multi-stage command and control (C2) attack with a malware variant of OSX. pirrit across our live customer traffic, signaling a strong indication this attack was more than benign adware. Trinity Cyber thwarted this attack on a U.S. university's network used by faculty, staff and students.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.