s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.irata

📛 Threat Title

Malware family: IRATA

Category: IRATA First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.irata`. Printable name: IRATA.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.irata VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.irata

IOC database

Type
domain
Value
apk.irata
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.irata

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.irata

References (1)

Remediations (10)

  • web:blog.kaymera.com

    Our focus, however, centers on the case of " IRATA ," a cunning malware specimen that primarily employs phishing as its means of infection. In the twisted web of IRATA's deceit, unsuspecting victims receive a seemingly legitimate SMS, complete with a link leading to a phishing page meticulously masquerading as a government service.

  • web:blog.rsisecurity.com

    Malware attacks are increasingly common cybersecurity concerns, as threat actors devise new, sophisticated approaches to infiltrate IT systems. As a result, every organization needs an effective malware remediation process to identify and mitigate malware attacks early on. Read on to learn about best practices for your organization. What are the Most Effective Malware Remediation Processes ...

  • web:malpedia.caad.fkie.fraunhofer.de

    According to redpiranha, IRATA (Iranian Remote Access Trojan) Android Malware is a new malware detected in the wild. It originates from a phishing attack through SMS. The theme of the message resembles information coming from the government that will ask you to download this malicious application. IRATA can collect sensitive information from your mobile phone including bank details. Since it ...

  • web:muha2xmad.github.io

    Technical analysis of IRATA android malware 23 minute read On this page Introduction Technical review Static analysis Explore AndroidManifest.xml Dive into classes.dex Dynamic analysis IoC Article Quote REF بسم الله الرحمن الرحيم FreePalestine Introduction In this blog, we will talk about IRATA . IRATA comes from a phishing attack to Iran. The victim receives a legitimate ...

  • web:nicolascoolman.eu

    On August 5, 2024, Symantec Broadcom's cybersecurity team reported a sophisticated SMishing campaign involving the IRATA Android malware .

  • web:static.redpiranha.net

    4. IRATA Android Malware IRATA (Iranian Remote Access Trojan) Android Malware is a new malware detected in the wild. It originates from a phishing attack through SMS. The theme of the message resembles information coming from the government that will ask you to download this malicious application.

  • web:threatfox.abuse.ch

    ThreatFox Database Indicators of Compromise (IOCs) on ThreatFox are associated with a certain malware fas. A malware sample can be associated with only one malware family . The page below gives you an overview on indicators of compromise associated with apk. irata . You can also get this data through the ThreatFox API. Database Entry

  • web:www.broadcom.com

    In recent weeks, a new IRATA campaign has been observed where the attackers used fake N26 Android applications (Certificato N26.apk) as a lure. N26 is a prominent mobile banking platform used widely throughout Europe.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.pcrisk.com

    What kind of malware is IRATA ? IRATA is the name of an Android-specific malware . This program has spyware and stealer capabilities. It was discovered after a smishing (SMS phishing) attack in Iran. This campaign entailed legitimate-looking SMSes containing a link to a fake governmental website. The page urged visitors to download an app and pay a fee for the service. It is noteworthy that ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.