s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.wroba

📛 Threat Title

Malware family: Wroba

Category: Wroba First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.wroba`. Printable name: Wroba.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.wroba VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.wroba

IOC database

Type
domain
Value
apk.wroba
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.wroba

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.wroba

References (1)

Remediations (10)

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as Wroba .

  • web:dl.acm.org

    A survey of android malware characterisitics and mitigation techniques. In Proceedings of the 11th International Conference on Information Technology: New Generations (2014), 327-332.

  • web:malpedia.caad.fkie.fraunhofer.de

    MoqHao, also called Wroba and XLoader (not to be confused with the malware of the same name for Windows and macOS), is an Android-based mobile threat that is associated with a financially motivated Chinese group called Roaming Mantis. The malware claims to be the default SMS application and has dropper and banker capabilities.

  • web:thehackernews.com

    Roaming Mantis spreading updated Wroba mobile malware that hijacks DNS settings of connected Wi-Fi routers for malicious attacks.

  • web:www.bleepingcomputer.com

    Starting in September 2022, the 'Roaming Mantis' credential theft and malware distribution campaign was observed using a new version of the Wroba.o/XLoader Android malware that incorporates a ...

  • web:www.kaspersky.com

    On January 19, Kaspersky researchers reported on a new domain name system (DNS) changer functionality used in the Roaming Mantis campaign. Now cybercriminals can use compromised Wi-Fi routers in cafes, airports hotels and other public places to potentially infect more Android smartphones with the Wroba.o malware . At the moment, the new technique targets users in South Korea, but it can be soon ...

  • web:www.linkedin.com

    Wroba (also known as MoqHao, XLoader on Android, or variants like Wroba.o) is a family of Android malware , primarily classified as a banking Trojan and backdoor.

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.msspalert.com

    The Roaming Mantis cyber threat crew (aka Shaoye) are attacking Wi-Fi routers in public locations to spread Android malware known as Wroba.o.

  • web:www.pcrisk.com

    Wroba malware overview Based on our research and analysis, Wroba is designed to infiltrate Android devices - execute malicious commands and steal data from infected systems. This malware begins its operations by gathering information about the mobile device.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.