TF-MAL-apk.flubot
📛 Threat Title
Malware family: FluBot
Description
ThreatFox malware family `apk.flubot`. Printable name: FluBot. Aliases: Cabassous,FakeChat.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.flubot
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.flubot
IOC database
- Type
- domain
- Value
apk.flubot- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.flubot
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.flubot
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
FluBot is a multi-purpose mobile banking malware that was first observed in Spain in late 2020. It primarily spread through European countries using a variety of SMS phishing messages in multiple languages.
-
web:dl.acm.org
Flubot , a specific type of smishing-based malware , is a recent large-scale example of smishing, which has affected millions of consumers and businesses in a fairly short time [74]. Fortunately for users, Flubot was taken down in early June of 2022 by a global cooperation of cyber police forces [24].
-
web:en.wikipedia.org
FluBot is a sophisticated SMS computer virus -specifically a banking Trojan - of global reach which aims to steal private data from Android smart phones. Unlike much malware , FluBot has proven exceptionally durable, coming in waves or "campaigns" with each redesign.
-
web:hacked.com
FluBot was a high-volume Android malware family spread through SMS ("smishing") that pushed people to install a fake delivery or voicemail app. It stole credentials, harvested contact lists ...
-
web:malpedia.caad.fkie.fraunhofer.de
PRODAFT describes FluBot as a banking malware which originally targeted Spain. Since the first quarter of 2021 it has been targeting many other European countries as well as Japan. It uses a DGA for it's C&C and relies on both DNS and DNS-over-HTTPS for name resolution. Despite arrests of multiple people suspected of involvement with this malware in March of 2021, the campaign has only ...
-
web:www.europol.europa.eu
An international law enforcement operation involving 11 countries has resulted in the takedown of one of the fastest-spreading mobile malware to date. Known as FluBot , this Android malware has been spreading aggressively through SMS, stealing passwords, online banking details and other sensitive information from infected smartphones across the world. Its infrastructure was successfully ...
-
web:www.incibe.es
An IOC rule and a Yara rule are also available in this analysis to help with detecting samples belonging to the FluBot family . General information. Summary of actions. Detailed analysis. Anti-detection and anti-reverse engineering techniques. Persistence.
-
web:www.pcrisk.com
What kind of malware is FluBot ? FluBot (also known as Cabassous) is malicious software that targets Android smartphones. Cyber criminals distribute FluBot via SMS messages, which they send (in at least in three different languages such as German, Polish, and Hungarian) with links to download websites for a fake FedEx application.
-
web:www.researchgate.net
Download Citation | On Oct 16, 2023, Artur Geers and others published Lessons in Prevention and Cure: A User Study of Recovery from Flubot Smartphone Malware | Find, read and cite all the research ...
-
web:www.swissinfo.ch
An international police operation has successfully prevented the rapid spread of the so-called FluBot malware .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.