TF-MAL-js.smokest
📛 Threat Title
Malware family: Smokest Stealer
Description
ThreatFox malware family `js.smokest`. Printable name: Smokest Stealer.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
js.smokest
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.smokest
IOC database
- Type
- domain
- Value
js.smokest- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-js.smokest
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.smokest
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:arstechnica.com
Once-hobbled Lumma Stealer is back with lures that are hard to resist ClickFix bait, combined with advanced Castleloader malware , is installing Lumma "at scale."
-
web:assets.kpmg.com
Stealth tactics include scanning for VMs & debugging tools, hiding malicious activities in background processes, and using trusted system tools to avoid detection. Lumma Stealer's exploitation of legitimate services and use of obfuscated payloads to steal sensitive information underscores the need for robust security measures to combat such ...
-
web:cybelangel.com
What is LummaC2 Stealer ? LummaC2, often shortened to Lumma, is an information-stealing malware written in C and first observed on Russian-speaking forums in mid-2022. It's sold as Malware -as-a-Service (MaaS), and marketed to cybercriminals who want a plug-and-play way to harvest sensitive data.
-
web:hunt.io
Discover detailed profiles of malware families, including threat actor data, mitigation strategies, and targeted industries to enhance your defenses.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Smokest Stealer malware family including references, samples and yara signatures.
-
web:outpost24.com
Outpost24's KrakenLabs team have taken a deep dive into the malware classified as LummaC2, an information stealer written in C language that has been sold in underground forums since December 2022. We assess LummaC2's primary workflow, its different obfuscation techniques (like Windows API hashing and encoded strings) and how to overcome them to effectively analyze the malware with ease ...
-
web:spycloud.com
Overall, the LummaC2 stealer continues to be a competent and serious threat to defenders and enterprises, and these changes and updates only aid in keeping LummaC2 competitive with other infostealer malware on the market. A graph comparing LummaC2 infections to other prevalent malware family infections.
-
web:unit42.paloaltonetworks.com
This article examines new obfuscation techniques the Gremlin stealer malware uses to conceal malicious payloads within embedded resources. We analyze a variant protected by a sophisticated commercial packing utility that employs instruction virtualization, transforming the original code into a custom, non-standard bytecode executed by a private ...
-
web:www.breachsense.com
Learn how to respond to malware incidents that steal credentials and session tokens. Discover how to remediate beyond device cleanup with this 7-step playbook.
-
web:www.microsoft.com
Over the past year, Microsoft Threat Intelligence observed the persistent growth and operational sophistication of Lumma Stealer , an info-stealing malware used by multiple financially motivated threat actors to target various industries. Microsoft, partnering with others across industry and international law enforcement, facilitated the disruption of Lumma infrastructure.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.