s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.flubot

📛 Threat Title

Malware family: FluBot

Category: FluBot First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.flubot`. Printable name: FluBot. Aliases: Cabassous,FakeChat.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.flubot VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.flubot

IOC database

Type
domain
Value
apk.flubot
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.flubot

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.flubot

References (1)

Remediations (10)

  • web:attack.mitre.org

    FluBot is a multi-purpose mobile banking malware that was first observed in Spain in late 2020. It primarily spread through European countries using a variety of SMS phishing messages in multiple languages.

  • web:dl.acm.org

    Flubot , a specific type of smishing-based malware , is a recent large-scale example of smishing, which has affected millions of consumers and businesses in a fairly short time [74]. Fortunately for users, Flubot was taken down in early June of 2022 by a global cooperation of cyber police forces [24].

  • web:en.wikipedia.org

    FluBot is a sophisticated SMS computer virus -specifically a banking Trojan - of global reach which aims to steal private data from Android smart phones. Unlike much malware , FluBot has proven exceptionally durable, coming in waves or "campaigns" with each redesign.

  • web:hacked.com

    FluBot was a high-volume Android malware family spread through SMS ("smishing") that pushed people to install a fake delivery or voicemail app. It stole credentials, harvested contact lists ...

  • web:malpedia.caad.fkie.fraunhofer.de

    PRODAFT describes FluBot as a banking malware which originally targeted Spain. Since the first quarter of 2021 it has been targeting many other European countries as well as Japan. It uses a DGA for it's C&C and relies on both DNS and DNS-over-HTTPS for name resolution. Despite arrests of multiple people suspected of involvement with this malware in March of 2021, the campaign has only ...

  • web:www.europol.europa.eu

    An international law enforcement operation involving 11 countries has resulted in the takedown of one of the fastest-spreading mobile malware to date. Known as FluBot , this Android malware has been spreading aggressively through SMS, stealing passwords, online banking details and other sensitive information from infected smartphones across the world. Its infrastructure was successfully ...

  • web:www.incibe.es

    An IOC rule and a Yara rule are also available in this analysis to help with detecting samples belonging to the FluBot family . General information. Summary of actions. Detailed analysis. Anti-detection and anti-reverse engineering techniques. Persistence.

  • web:www.pcrisk.com

    What kind of malware is FluBot ? FluBot (also known as Cabassous) is malicious software that targets Android smartphones. Cyber criminals distribute FluBot via SMS messages, which they send (in at least in three different languages such as German, Polish, and Hungarian) with links to download websites for a fake FedEx application.

  • web:www.researchgate.net

    Download Citation | On Oct 16, 2023, Artur Geers and others published Lessons in Prevention and Cure: A User Study of Recovery from Flubot Smartphone Malware | Find, read and cite all the research ...

  • web:www.swissinfo.ch

    An international police operation has successfully prevented the rapid spread of the so-called FluBot malware .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.