s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.eugenloader

📛 Threat Title

Malware family: EugenLoader

Category: EugenLoader First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.eugenloader`. Printable name: EugenLoader. Aliases: FakeBat,NUMOZYLOD,PaykLoader.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain ps1.eugenloader VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ps1.eugenloader

IOC database

Type
domain
Value
ps1.eugenloader
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-ps1.eugenloader

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ps1.eugenloader

References (1)

Remediations (10)

  • web:cybersecsentinel.com

    Security Advisory Report: FakeBat Malware Summary FakeBat, also known as EugenLoader or PaykLoader, has emerged as a significant threat in 2024, spreading through drive-by download attacks and malvertising campaigns. Distributed under a Loader-as-a-Service (LaaS) model by the Russian-speaking threat actor Eugenfest, FakeBat targets victims through compromised websites, fake browser updates,

  • web:malpedia.caad.fkie.fraunhofer.de

    EugenLoader POWERTRASH BATLOADER DarkGate FlawedGrace NetSupportManager RAT SectopRAT Storm-0506 2023-12-12 ⋅ eSentire ⋅ Rob Pittman Unraveling BatLoader and FakeBat EugenLoader 2023-02-28 ⋅ Intel 471 ⋅ Intel 471 Malvertising Surges to Distribute Malware EugenLoader BATLOADER IcedID

  • web:nquiringminds.com

    Cybersecurity researchers have identified a surge in malware infections caused by malvertising campaigns distributing FakeBat [1] [3], also known as EugenLoader and PaykLoader [1] [3]. Description This malware , linked to threat actor Eugenfest and tracked by the Google-owned threat intelligence team as NUMOZYLOD [3], is associated with the UNC4536 group [1]. UNC4536 uses malvertising to ...

  • web:securitricks.com

    Description During the first semester of 2024, FakeBat (aka EugenLoader , PaykLoader) was one of the most widespread loaders using the drive-by download technique. Researchers uncovered multiple FakeBat distribution campaigns leveraging malvertising, software impersonation, fake web browser updates, and social engineering schemes on social networks to trick users into downloading the malware ...

  • web:threatfox.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on indicators of compromise associated with ps1. eugenloader .

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.mphasis.ai

    Summary FakeBat (also known as EugenLoader ) is a malicious software loader and dropper that has emerged as a significant player in the world of cyber threats. FakeBat utilizes multiple delivery tactics, with malvertising being the primary strategy. This involves exploiting online advertising platforms, including Google Ads, to spread the malware .

  • web:www.mphasis.com

    Summary FakeBat (also known as EugenLoader ) is a malicious software loader and dropper that has emerged as a significant player in the world of cyber threats. FakeBat utilizes multiple delivery tactics, with malvertising being the primary strategy. This involves exploiting online advertising platforms, including Google Ads, to spread the malware .

  • web:www.sos-vo.org

    The Mandiant Managed Defense team has discovered an increase in malware infections caused by malvertising campaigns that distribute a loader named "FakeBat," also known as " EugenLoader " and "PaykLoader." The researchers consider these attacks "opportunistic," as they are aimed at users looking to download popular business software.

  • web:www.threatdown.com

    FakeBat, tested on May 5, 2024 FakeBat ( EugenLoader ) is a type of malware loader packaged in Microsoft installers (MSI or MSIX) distributed via social engineering lures. It is most commonly delivered via malicious ads (malvertising) on Google. The often large installers conceal a malicious PowerShell script responsible for communicating with the malicious infrastructure and retrieving a ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.