s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-jar.versamem

📛 Threat Title

Malware family: VersaMem

Category: VersaMem First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `jar.versamem`. Printable name: VersaMem.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain jar.versamem VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.versamem

IOC database

Type
domain
Value
jar.versamem
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-jar.versamem

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.versamem

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    The deployment of the VersaMem web shell allows threat actors to gain deep access to network configurations and potentially pivot into downstream networks. Given the severity of the vulnerability and the sophistication of the attack, it is crucial for affected entities to upgrade to the software version and implement the recommended mitigation ...

  • web:attack.mitre.org

    VersaMem is a web shell designed for deployment to Versa Director servers following exploitation. Discovered in August 2024, VersaMem was used during Versa Director Zero Day Exploitation by Volt Typhoon to target ISPs and MSPs.

  • web:cyberinsider.com

    A zero-day in Versa Director has been actively exploited by the Chinese state-sponsored threat group Volt Typhoon in attacks against ISPs.

  • web:cybernoz.com

    Advanced, persistent attackers have exploited a zero-day vulnerability (CVE-2024-39717) in Versa Director to compromise US-based managed service providers with a custom-made web shell dubbed VersaMem by the researchers. The malware harvests credentials enabling the attackers to access the providers' downstream customers' networks as an authenticated user. "Based on known and observed ...

  • web:cyberpress.org

    Chinese state-sponsored threat actors Volt Typhoon and Bronze Silhouette exploited a zero-day vulnerability (CVE-2024-39717) in Versa Director servers, which allows attackers to gain administrative access and deploy a custom web shell, VersaMem , to intercept and harvest credentials.

  • web:cybersecuritynews.com

    Chinese state-sponsored threat actors have been exploiting a zero-day vulnerability in Versa Director servers, identified as CVE-2024-39717.

  • web:malpedia.caad.fkie.fraunhofer.de

    jar. versamem (Back to overview) VersaMem Propose Change Actor (s): Volt Typhoon According to Lumen, a web shell used by Volt Typhoon.

  • web:misp-galaxy.org

    VersaMem is a web shell designed for deployment to Versa Director servers following exploitation. Discovered in August 2024, VersaMem was used during Versa Director Zero Day Exploitation by Volt Typhoon to target ISPs and MSPs. VersaMem is deployed as a Java Archive (JAR) and allows for credential capture for Versa Director logon activity as well as follow-on execution of arbitrary Java ...

  • web:www.csoonline.com

    The Chinese APT group leveraged the vulnerability to deploy a web shell that stole credentials from Versa Director SD-WAN deployments of ISPs, MSPs, and IT companies.

  • web:www.lumen.com

    Malware analysis The web shell, referred to as " VersaMem ," was first uploaded to VirusTotal from Singapore on June 7, 2024, with the filename "VersaTest.png," approximately five days prior to the earliest exploitation of Versa Director servers Black Lotus Labs was able to identify in the U.S.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.