TF-MAL-elf.conti
📛 Threat Title
Malware family: Conti
Description
ThreatFox malware family `elf.conti`. Printable name: Conti. Aliases: Conti Locker.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.conti
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.conti
IOC database
- Type
- domain
- Value
elf.conti- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.conti
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.conti
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybersecuritynews.com
The move from a Conti -based locker to Gunra's own ransomware is central to how the group expanded its RaaS operations. Initially, relying on established Conti code gave the operators a fast way to launch attacks, but it also placed limits on how much they could customize their tools and panel features.
-
web:darkatlas.io
<p>Executive Summary Conti ransomware, first identified in 2019, quickly became one of the most notorious ransomware operations due to its advanced encryption, rapid lateral movement, and use of double extortion tactics. Operated as a Ransomware-as-a-Service (RaaS) by the Russia-based Wizard Spider group, Conti is believed to have evolved from Ryuk ransomware and maintained suspected ties ...
-
web:data-guard365.com
Here's an in-depth analysis of Conti ransomware, along with information on detection and mitigation strategies. Conti ransomware analysis.
-
web:en.wikipedia.org
Conti is malware developed and first used by the Russia -based hacking group "Wizard Spider" in December, 2019. [1][2] It has since become a full-fledged ransomware-as-a-service (RaaS) operation used by numerous threat actor groups to conduct ransomware attacks.
-
web:malpedia.caad.fkie.fraunhofer.de
Conti Hive BlackByte BlackCat Clop LockBit Mespinoza Ragnarok 2022-06-15 ⋅ ThreatStop ⋅ Ofir Ashman First Conti , then Hive: Costa Rica gets hit with ransomware again Conti Hive Conti Hive 2022-05-12 ⋅ Intel 471 ⋅ Intel 471 What malware to look for if you want to prevent a ransomware attack Conti BumbleBee Cobalt Strike IcedID Sliver
-
web:threatcop.com
Conti ransomware is a highly sophisticated malware used by cybercriminals to encrypt data and demand ransom, targeting businesses and organizations worldwide.
-
web:www.cisa.gov
To secure systems against Conti ransomware, implementing the mitigation measures described in this Advisory, which include requiring multifactor authentication (MFA), implementing network segmentation, and keeping operating systems and software up to date.
-
web:www.malwarebytes.com
All component/technology detections are passed to the remediation engine for complete removal from infected systems. This industry leading technology uses patented techniques in identifying all cohorts or associated files for a single threat and removes them all together to prevent malware from resuscitating itself.
-
web:www.sentinelone.com
Conti Ransomware Technical Details Conti is an aggressive and prolific ransomware family with functional ties to Trickbot and Ryuk. The authors and affiliates of the ransomware boast that it has stronger encryption and is faster than its predecessors. It also has improved obfuscation and scope.
-
web:www.thodex.com
Detection and Mitigation Strategies Detecting and mitigating the threat of Conti ransomware requires a comprehensive and multi-layered approach. SentinelOne's Singularity XDR Platform is designed to detect and halt Conti -related activities effectively.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.