TF-MAL-apk.xhelper
📛 Threat Title
Malware family: xHelper
Description
ThreatFox malware family `apk.xhelper`. Printable name: xHelper.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.xhelper
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.xhelper
IOC database
- Type
- domain
- Value
apk.xhelper- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.xhelper
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.xhelper
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (9)
-
web:bazaar.abuse.ch
Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with xhelper .
-
web:deepwiki.com
The xHelper malware family represents a sophisticated Android threat characterized by extensive permission requests and comprehensive system access capabilities.
-
web:en.softonic.com
A little over two years ago, a brand new type of malware burst onto the Android scene. The story of this particular piece of malware first appeared in the news cycle over at Android Police. In an article released in April 2020, AP explained that the malware , named xHelper , was able to survive even the most thorough And roid factory resettin g regimen.
-
web:en.todoandroid.es
Learn how xHelper , the impossible-to-remove malware on Android, works, its risks, and the best strategies to protect your phone.
-
web:malpedia.caad.fkie.fraunhofer.de
Xhelper is a very persistent malware that can reinstall itself after factory reset, Xhelper downloads malicious apps and displays annoying ads.
-
web:www.infosecinstitute.com
How to prevent xHelper It is always recommended to install an antivirus program for Android that can detect malware before being deployed on the system. If you suspect malware , download a legitimate anti- malware program that protects against the Trojan.Dropper. xHelper at least to a certain degree.
-
web:www.malwarebytes.com
Android/Trojan.Dropper. xHelper drops an encrypted DEX file with a .jar extension on the affected devices. Android/Trojan.Dropper. xHelper is most likely being spread by web redirects. Protection Malwarebytes for Android protects against Android/Trojan.Dropper. xHelper . Remediation Malwarebytes for Android is able to remove Android/Trojan.Dropper ...
-
web:www.programmersought.com
Symantec researchers discovered a malicious Android application- Xhelper . The program can hide itself, download other malicious apps, and display ads. And most importantly, Xhelper is permanent. After the user uninstalls Xhelper , the malware can be reinstalled and can hide itself from appearing in the system's launcher. In the past 6 months, Xhelper has infected more than 45,000 devices.
-
web:www.threatdown.com
Android/Trojan.Dropper. xHelper drops an encrypted DEX file with a .jar extension on the affected devices. Android/Trojan.Dropper. xHelper is most likely being spread by web redirects.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Reputation of linked indicators
DomScan scores the domains, AbuseIPDB + GreyNoise score the IPs. Verdicts are per-indicator — this is a roll-up, so no lookup is triggered by opening this page.
| Indicator | Type | Verdict | Score |
|---|---|---|---|
apk.xhelper |
domain | high | 44 |