s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

OTX-686e30d838dba7fcc8e24758 high

📛 Threat Title

MobSF - C2 IP/Domain Tracker

Category: MobSF Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

This pulse contains IOCs related to MobSF Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 78.47.51.234 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/78.47.51.234

IOC database

Type
ipv4
Value
78.47.51.234
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/78.47.51.234

References (1)

  • OTX pulse AlienVaulkt OTX

    This pulse contains IOCs related to MobSF Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.

Remediations (8)

  • web:attack.mitre.org

    Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection. Use of Web services may also protect back-end C2 infrastructure from discovery through malware binary analysis while also enabling operational resiliency (since this infrastructure may be dynamically changed).

  • web:cheatsheetseries.owasp.org

    Server-Side Request Forgery Prevention Cheat Sheet Introduction The objective of the cheat sheet is to provide advices regarding the protection against Server Side Request Forgery (SSRF) attack. This cheat sheet will focus on the defensive point of view and will not explain how to perform this attack. This talk from the security researcher Orange Tsai as well as this document provide ...

  • web:deepwiki.com

    This section documents MobSF's malware and tracker detection capabilities during static analysis. These features identify known malicious patterns, domains, and privacy-invasive components embedded in mobile applications through integration with external threat intelligence sources and signature databases.

  • web:github.com

    Mobile Security Framework ( MobSF ) Mobile Security Framework ( MobSF ) is a security research platform for mobile applications in Android, iOS and Windows Mobile. MobSF can be used for a variety of use cases such as mobile application security, penetration testing, malware analysis, and privacy analysis.

  • web:mobsf.org

    MobSF is designed to simplify and automate the complex process of mobile application security testing. Its main goal is to make vulnerability detection accessible to both developers and security professionals.

  • web:pypi.org

    Mobile Security Framework ( MobSF ) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.

  • web:www.cyberdefenseinsight.com

    Cybercriminals continuously evolve their methods to exploit legitimate tools for malicious purposes. They have repurposed NetSupport Manager, originally designed for remote system management, into a Remote Access Trojan (RAT). Security researchers recently detected a new infection chain called #SmartApeSG, which delivers NetSupport RAT and StealC malware through fake browser updates.

  • web:www.stepsecurity.io

    We have responsibly disclosed the issue to the project maintainers. StepSecurity Harden-Runner, whose community tier is free for public repos and is used by over 12,000 public repositories, detected the compromised axios package making anomalous outbound connections to the attacker's C2 domain across multiple open source projects.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…