TF-MAL-elf.cronrat
📛 Threat Title
Malware family: CronRAT
Description
ThreatFox malware family `elf.cronrat`. Printable name: CronRAT.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.cronrat
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.cronrat
IOC database
- Type
- domain
- Value
elf.cronrat- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.cronrat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.cronrat
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybersecuritynews.com
Microsoft has released urgent security updates to address a zero-day vulnerability in the Windows Cloud Files Mini Filter Driver (cldflt.sys) that is currently being exploited in the wild.
-
web:malpedia.caad.fkie.fraunhofer.de
A malware written in Bash that hides in the Linux calendar system on February 31st. Observed in relation to Magecart attacks.
-
web:sansec.io
Last week we analyzed a clever malware attacking online stores, and today we expose another, much more sophisticated threat. It is a Remote Access Trojan (RAT) and we have named it CronRAT . Sansec found CronRAT to be present on multiple online stores, among them a nation's largest outlet. Because of its novel execution, we had to rewrite part of our eComscan algorithm in order to detect it ...
-
web:www.admin-magazine.com
The new CronRAT attack can execute fileless malware , launch malware in separate subsystems, control servers disguised as Dropbear SSH services, hide payloads in legitimate cron tasks, and run anti-tampering commands. CronRAT bypasses browser-based security scans and has already been discovered in live online stores.
-
web:www.bleepingcomputer.com
The latest news about CronRAT New malware hides as legit nginx process on e-commerce servers eCommerce servers are being targeted with remote access malware that hides on Nginx servers in a way ...
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.fbi.gov
Threat actors exploit physical and software vulnerabilities in ATMs and deploy malware to dispense cash without a legitimate transaction. The FBI has observed an increase in ATM jackpotting ...
-
web:www.ncsc.gov.uk
How to defend organisations against malware or ransomware attacks.
-
web:www.quorumcyber.com
The CronRAT malware hides its payloads in the cron tab (Linux's task scheduler). However, unlike a traditional scheduled task, CronRAT entries use non-existent dates (such as February 31st) to prevent the task from ever being triggered.
-
web:www.trendmicro.com
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.It requires being executed with a specific argument/parameter, an additional component, or in a specific environment in order to proceed with its intended routine.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.