TF-MAL-js.parasitesnatcher
📛 Threat Title
Malware family: ParaSiteSnatcher
Description
ThreatFox malware family `js.parasitesnatcher`. Printable name: ParaSiteSnatcher.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
js.parasitesnatcher
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.parasitesnatcher
IOC database
- Type
- domain
- Value
js.parasitesnatcher- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-js.parasitesnatcher
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.parasitesnatcher
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
ParaSiteSnatcher is designed to work on Chromium-based browsers, expanding its potential impact beyond Google Chrome. The malware is delivered through a VBScript downloader with three distinct variants, each varying in obfuscation complexity.
-
web:blog.netmanageit.com
The ParaSiteSnatcher framework allows threat actors to monitor, manipulate, and exfiltrate highly sensitive information from multiple sources. ParaSiteSnatcher also utilizes the powerful Chrome Browser API to intercept and exfiltrate all POST requests containing sensitive account and financial information before the HTTP request initiates a ...
-
web:candid.technology
ParaSiteSnatcher is equipped with extensive permissions, allowing it to manipulate web sessions, requests and track user interactions across multiple tabs using Chrome tabs API. The malware includes components that facilitate code injection into web pages, monitor Chrome tabs, and intercept user input and web browser communication.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the ParaSiteSnatcher malware family including references, samples and yara signatures.
-
web:vulners.com
We detail the modular framework of malicious Chrome extensions that consist of various highly obfuscated components that leverage Google Chrome API to monitor, intercept, and exfiltrate victim data.
-
web:www.breachsense.com
Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.hivepro.com
Attack: ParaSiteSnatcher is a malicious Google Chrome extension designed to target users in Latin America, particularly Brazil. It specifically focuses on Chromium-based browsers like Microsoft Edge, Brave, and Opera, with potential compatibility with Firefox and Safari.
-
web:www.ncsc.gov.uk
How to defend organisations against malware or ransomware attacks.
-
web:www.threatshub.org
The ParaSiteSnatcher framework allows threat actors to monitor, manipulate, and exfiltrate highly sensitive information from multiple sources. ParaSiteSnatcher also utilizes the powerful Chrome Browser API to intercept and exfiltrate all POST requests containing sensitive account and financial information before the HTTP request initiates a ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.