TF-MAL-jar.versamem
📛 Threat Title
Malware family: VersaMem
Description
ThreatFox malware family `jar.versamem`. Printable name: VersaMem.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
jar.versamem
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.versamem
IOC database
- Type
- domain
- Value
jar.versamem- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-jar.versamem
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.versamem
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
The deployment of the VersaMem web shell allows threat actors to gain deep access to network configurations and potentially pivot into downstream networks. Given the severity of the vulnerability and the sophistication of the attack, it is crucial for affected entities to upgrade to the software version and implement the recommended mitigation ...
-
web:attack.mitre.org
VersaMem is a web shell designed for deployment to Versa Director servers following exploitation. Discovered in August 2024, VersaMem was used during Versa Director Zero Day Exploitation by Volt Typhoon to target ISPs and MSPs.
-
web:cyberinsider.com
A zero-day in Versa Director has been actively exploited by the Chinese state-sponsored threat group Volt Typhoon in attacks against ISPs.
-
web:cybernoz.com
Advanced, persistent attackers have exploited a zero-day vulnerability (CVE-2024-39717) in Versa Director to compromise US-based managed service providers with a custom-made web shell dubbed VersaMem by the researchers. The malware harvests credentials enabling the attackers to access the providers' downstream customers' networks as an authenticated user. "Based on known and observed ...
-
web:cyberpress.org
Chinese state-sponsored threat actors Volt Typhoon and Bronze Silhouette exploited a zero-day vulnerability (CVE-2024-39717) in Versa Director servers, which allows attackers to gain administrative access and deploy a custom web shell, VersaMem , to intercept and harvest credentials.
-
web:cybersecuritynews.com
Chinese state-sponsored threat actors have been exploiting a zero-day vulnerability in Versa Director servers, identified as CVE-2024-39717.
-
web:malpedia.caad.fkie.fraunhofer.de
jar. versamem (Back to overview) VersaMem Propose Change Actor (s): Volt Typhoon According to Lumen, a web shell used by Volt Typhoon.
-
web:misp-galaxy.org
VersaMem is a web shell designed for deployment to Versa Director servers following exploitation. Discovered in August 2024, VersaMem was used during Versa Director Zero Day Exploitation by Volt Typhoon to target ISPs and MSPs. VersaMem is deployed as a Java Archive (JAR) and allows for credential capture for Versa Director logon activity as well as follow-on execution of arbitrary Java ...
-
web:www.csoonline.com
The Chinese APT group leveraged the vulnerability to deploy a web shell that stole credentials from Versa Director SD-WAN deployments of ISPs, MSPs, and IT companies.
-
web:www.lumen.com
Malware analysis The web shell, referred to as " VersaMem ," was first uploaded to VirusTotal from Singapore on June 7, 2024, with the filename "VersaTest.png," approximately five days prior to the earliest exploitation of Versa Director servers Black Lotus Labs was able to identify in the U.S.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.