TF-MAL-apk.irata
📛 Threat Title
Malware family: IRATA
Description
ThreatFox malware family `apk.irata`. Printable name: IRATA.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.irata
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.irata
IOC database
- Type
- domain
- Value
apk.irata- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.irata
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.irata
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.kaymera.com
Our focus, however, centers on the case of " IRATA ," a cunning malware specimen that primarily employs phishing as its means of infection. In the twisted web of IRATA's deceit, unsuspecting victims receive a seemingly legitimate SMS, complete with a link leading to a phishing page meticulously masquerading as a government service.
-
web:blog.rsisecurity.com
Malware attacks are increasingly common cybersecurity concerns, as threat actors devise new, sophisticated approaches to infiltrate IT systems. As a result, every organization needs an effective malware remediation process to identify and mitigate malware attacks early on. Read on to learn about best practices for your organization. What are the Most Effective Malware Remediation Processes ...
-
web:malpedia.caad.fkie.fraunhofer.de
According to redpiranha, IRATA (Iranian Remote Access Trojan) Android Malware is a new malware detected in the wild. It originates from a phishing attack through SMS. The theme of the message resembles information coming from the government that will ask you to download this malicious application. IRATA can collect sensitive information from your mobile phone including bank details. Since it ...
-
web:muha2xmad.github.io
Technical analysis of IRATA android malware 23 minute read On this page Introduction Technical review Static analysis Explore AndroidManifest.xml Dive into classes.dex Dynamic analysis IoC Article Quote REF بسم الله الرحمن الرحيم FreePalestine Introduction In this blog, we will talk about IRATA . IRATA comes from a phishing attack to Iran. The victim receives a legitimate ...
-
web:nicolascoolman.eu
On August 5, 2024, Symantec Broadcom's cybersecurity team reported a sophisticated SMishing campaign involving the IRATA Android malware .
-
web:static.redpiranha.net
4. IRATA Android Malware IRATA (Iranian Remote Access Trojan) Android Malware is a new malware detected in the wild. It originates from a phishing attack through SMS. The theme of the message resembles information coming from the government that will ask you to download this malicious application.
-
web:threatfox.abuse.ch
ThreatFox Database Indicators of Compromise (IOCs) on ThreatFox are associated with a certain malware fas. A malware sample can be associated with only one malware family . The page below gives you an overview on indicators of compromise associated with apk. irata . You can also get this data through the ThreatFox API. Database Entry
-
web:www.broadcom.com
In recent weeks, a new IRATA campaign has been observed where the attackers used fake N26 Android applications (Certificato N26.apk) as a lure. N26 is a prominent mobile banking platform used widely throughout Europe.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.pcrisk.com
What kind of malware is IRATA ? IRATA is the name of an Android-specific malware . This program has spyware and stealer capabilities. It was discovered after a smishing (SMS phishing) attack in Iran. This campaign entailed legitimate-looking SMSes containing a link to a fake governmental website. The page urged visitors to download an app and pay a fee for the service. It is noteworthy that ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.