s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.cronrat

📛 Threat Title

Malware family: CronRAT

Category: CronRAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.cronrat`. Printable name: CronRAT.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.cronrat VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.cronrat

IOC database

Type
domain
Value
elf.cronrat
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.cronrat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.cronrat

References (1)

Remediations (10)

  • web:cybersecuritynews.com

    Microsoft has released urgent security updates to address a zero-day vulnerability in the Windows Cloud Files Mini Filter Driver (cldflt.sys) that is currently being exploited in the wild.

  • web:malpedia.caad.fkie.fraunhofer.de

    A malware written in Bash that hides in the Linux calendar system on February 31st. Observed in relation to Magecart attacks.

  • web:sansec.io

    Last week we analyzed a clever malware attacking online stores, and today we expose another, much more sophisticated threat. It is a Remote Access Trojan (RAT) and we have named it CronRAT . Sansec found CronRAT to be present on multiple online stores, among them a nation's largest outlet. Because of its novel execution, we had to rewrite part of our eComscan algorithm in order to detect it ...

  • web:www.admin-magazine.com

    The new CronRAT attack can execute fileless malware , launch malware in separate subsystems, control servers disguised as Dropbear SSH services, hide payloads in legitimate cron tasks, and run anti-tampering commands. CronRAT bypasses browser-based security scans and has already been discovered in live online stores.

  • web:www.bleepingcomputer.com

    The latest news about CronRAT New malware hides as legit nginx process on e-commerce servers eCommerce servers are being targeted with remote access malware that hides on Nginx servers in a way ...

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.fbi.gov

    Threat actors exploit physical and software vulnerabilities in ATMs and deploy malware to dispense cash without a legitimate transaction. The FBI has observed an increase in ATM jackpotting ...

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

  • web:www.quorumcyber.com

    The CronRAT malware hides its payloads in the cron tab (Linux's task scheduler). However, unlike a traditional scheduled task, CronRAT entries use non-existent dates (such as February 31st) to prevent the task from ever being triggered.

  • web:www.trendmicro.com

    This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.It requires being executed with a specific argument/parameter, an additional component, or in a specific environment in order to proceed with its intended routine.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.