s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.moqhao

📛 Threat Title

Malware family: MoqHao

Category: MoqHao First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.moqhao`. Printable name: MoqHao. Aliases: Shaoye,Wroba,XLoader.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.moqhao VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.moqhao

IOC database

Type
domain
Value
apk.moqhao
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.moqhao

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.moqhao

References (1)

Remediations (10)

  • web:blog.netmanageit.com

    Description A recent variant of the Android malware MoqHao has been found to automatically execute itself upon installation without requiring user interaction. The malware is distributed via SMS phishing links and abuses legitimate services like URL shorteners and Pinterest. It targets users in Asia and Europe, collects device info, and contains many new command and control capabilities.

  • web:imtr.net

    The analysis focuses on the malware family named in the article title, " MoqHao ." ## Activity Summary The article describes the **evolution of MoqHao **, specifically noting that new variants exhibit the behavior of **automatically starting right after installation.**

  • web:malware.news

    Authored by Dexter Shin MoqHao is a well-known Android malware family associated with the Roaming Mantis threat actor group first discovered in 2015. McAfee Mobile Research Team has also posted several articles related to this malware family that traditionally targets Asian countries such as Korea and Japan. Recently McAfee Mobile Research Team found that MoqHao began distributing variants ...

  • web:malwaretips.com

    MoqHao Android Malware Evolves with Auto-Execution Capability A new variant of MoqHao Android malware silently auto-executes upon installation, snatching data, and hijacking Wi-Fi.

  • web:shadowshell.io

    We will also implement YARA rules to detect the malware and Java code to unpack the embedded payload. Executive summary The analyzed sample is an XLoader (also known as MoqHao ) Android banking trojan. It uses a loader APK that decrypts and runs an encrypted DEX payload at runtime.

  • web:www.anomali.com

    Anomali Cyber Watch: Volt Typhoon persistence in critical infrastructure and MoqHao variants. Key takeaways, IOCs, and hardening guidance.

  • web:www.cyberswissguards.com

    MoqHao malware family is an active malware that has been around for years. Although many years have passed, they are using more and more different ways to hide and reach users. We are seeing a much higher number of C2 commands than in previous, the active use of legitimate sites like Pinterest to store and update phishing data, and code with the potential to target Asian countries like Japan ...

  • web:www.linkedin.com

    Threat hunters have identified a new variant of Android malware called MoqHao that automatically executes on infected devices without requiring any user interaction. "Typical MoqHao requires users ...

  • web:www.mcafee.com

    Authored by Dexter Shin MoqHao is a well-known Android malware family associated with the Roaming Mantis threat actor group first discovered in 2015.

  • web:www.telekom.com

    Moqhao is something like the bestseller from the Roaming Mantis malware family , ready to build a backdoor into your smartphone's Android operating system. This group of Android malware is a proprietary brand of the Yanbian Gang.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.