TF-MAL-apk.smsspy
📛 Threat Title
Malware family: SMSspy
Description
ThreatFox malware family `apk.smsspy`. Printable name: SMSspy.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.smsspy
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.smsspy
IOC database
- Type
- domain
- Value
apk.smsspy- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.smsspy
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.smsspy
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:bazaar.abuse.ch
Malware samples associated with tag SmsSpy MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with SmsSpy . Database Entry
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the SMSspy malware family including references, samples and yara signatures.
-
web:malwaretips.com
The SMS Spy fake alert is a social engineering attack that tries to trick you into installing a malicious app or subscribing to unneeded paid services.
-
web:vms.drweb.com
Malicious functions: Sends SMS: +918910183743: <SMS Content> Sends data of incoming SMS to a remote host. Network activity: Connects to: UDP(DNS) 8####.8.4.4:53 ...
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.f-secure.com
SmsSpy.A as seen from 'Manage applications' and the permissions it requested. While apps with such behavior may be legitimately used by the device's authorized user, they are classified by security programs as riskware because in the hands of unauthorized users, they can also be used to cause damage to the user's data or the device.
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
-
web:www.ncsc.gov.uk
This guidance helps private and public sector organisations deal with the effects of malware (which includes ransomware). It provides actions to help organisations prevent a malware infection, and also steps to take if you're already infected. Following this guidance will reduce: the likelihood of becoming infected the spread of malware throughout your organisation the impact of the infection
-
web:www.pcrisk.com
What is SMSSpy ? SMSSpy refers to a piece of malicious software masquerading as various applications of legitimate e-commerce platforms. This malware aims to obtain victims' online banking credentials and thus gain access to the funds stored in the accounts. At the time we researched SMSSpy , it targeted Malaysian users exclusively.
-
web:www.trendmicro.com
Stop phishing, malware , ransomware, fraud, and targeted attacks from infiltrating your enterprise Stop phishing, ransomware, and targeted attacks on any email service including Microsoft 365 and Google Workspace End-to-end identity security from identity posture management to detection and response
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.