WHOIS API
Analysis of RisePro Malware Indicators and Artifacts
Pages
9
Time to read
7 mins
Language
English
Pages
9
Time to read
7 mins
Language
English
This technical report presents an analysis of the RisePro malware, a data stealer that has been affecting users since 2022. The report identifies ten indicators of compromise (IoCs), including three domains and seven IP addresses, discovered by ANY.RUN. The WhoisXML API research team expanded the IoC list to uncover additional threat artifacts, revealing 849 email-connected domains, 52 of which were found to be malicious, along with two additional malicious IP addresses. The report details the administrative registrars and creation years of the identified domains, as well as the geolocation of the IP addresses. Furthermore, it documents the findings from a bulk WHOIS lookup and a Reverse WHOIS API query, which led to the identification of further malicious domains associated with phishing and malware distribution. The report concludes with a cautionary note regarding the classification of threats and the importance of further investigation.