TF-MAL-elf.redtail
📛 Threat Title
Malware family: RedTail
Description
ThreatFox malware family `elf.redtail`. Printable name: RedTail.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.redtail
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.redtail
IOC database
- Type
- domain
- Value
elf.redtail- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.redtail
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.redtail
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as RedTail .
-
web:blog.netmanageit.com
This analysis focuses on redtail , a cryptocurrency mining malware that stealthily installs itself on compromised systems. The malware utilizes two additional scripts: one to identify the CPU architecture and another to remove existing cryptomining software.
-
web:globalcyberalliance.org
RedTail exploited known vulnerabilities, deployed customized binaries across multiple architectures, and maintained active infrastructure for months at a time.
-
web:isc.sans.edu
In summary, redtail malware demonstrates the evolving sophistication of cryptomining threats, using scripts to identify CPU architecture and remove competing miners, while also exploiting system vulnerabilities for root access.
-
web:malpedia.caad.fkie.fraunhofer.de
RedTail is a cryptomining malware , which is based on the open-source XMRIG mining software. It is being spread via known vulnerabilities such as: - CVE-2024-3400 - CVE-2023-46805 - CVE-2024-21887 - CVE-2023-1389 - CVE-2022-22954 - CVE-2018-20062
-
web:securitricks.com
Description This analysis focuses on redtail , a cryptocurrency mining malware that stealthily installs itself on compromised systems. The malware utilizes two additional scripts: one to identify the CPU architecture and another to remove existing cryptomining software. Observed attacks originated from IP addresses in the Netherlands and Bulgaria. The malware exploits weak root login ...
-
web:socprime.com
The article details a cryptomining campaign involving the redtail malware family , which is delivered through HTTP requests that exploit CVE-2024-4577 in PHP. Threat actors send Base64-encoded payloads that retrieve and run a self-replicating script named cve_2024_4577.selfrep.
-
web:undercodenews.com
2025-01-09 Cryptocurrency mining malware has become a significant threat in the cybersecurity landscape, with attackers constantly evolving their tactics to exploit system vulnerabilities. Among these threats, Redtail stands out as a particularly sophisticated cryptomining malware . This article delves into the intricate workings of Redtail , its advanced tactics, and the broader implications of ...
-
web:www.broadcom.com
Redtail is an adaptable malware that stealthily installs itself on compromised systems utilizing advanced tactics to persist and exploit systems for unauthorized cryptocurrency mining.
-
web:www.cloudtango.net
From August to November 2024, various malicious activities were recorded, including multiple incidents involving a cryptocurrency mining malware known as " Redtail ". This report delves into how Redtail operates, its advanced tactics, and strategies to counter its threat. Redtail exploits compromised systems to mine cryptocurrency without authorisation, using scripts to ensure compatibility ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.