TF-MAL-elf.avoslocker
📛 Threat Title
Malware family: Avoslocker
Description
ThreatFox malware family `elf.avoslocker`. Printable name: Avoslocker.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.avoslocker
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.avoslocker
IOC database
- Type
- domain
- Value
elf.avoslocker- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.avoslocker
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.avoslocker
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
AvosLocker is ransomware written in C++ that has been offered via the Ransomware-as-a-Service (RaaS) model. It was first observed in June 2021 and has been used against financial services, critical manufacturing, government facilities, and other critical infrastructure sectors in the United States.
-
web:blog.netmanageit.com
Description The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint Cybersecurity Advisory (CSA) to disseminate known IOCs, TTPs, and detection methods associated with the AvosLocker variant identified through FBI investigations as recently as May 2023. AvosLocker operates under a ransomware-as-a-service (RaaS) model ...
-
web:thrive.trellix.com
Summary Description of Campaign A month-long AvosLocker campaign was discovered using multiple tools to carry out the infection process including Cobalt Strike, Sliver, PDQ Deploy, AnyDesk, Mimikatz, and SoftPerfect Network Scanner. Multiple encoded PowerShell commands along with WMIC were used to download the tools and move laterally across the network. The attacker leveraged the Log4Shell ...
-
web:www.anvilogic.com
CISA and FBI release updated details on the AvosLocker ransomware gang, their techniques, and recommended mitigation steps for organizations. Learn about the recent ransomware trends.
-
web:www.attackiq.com
Files matching an extension list are identified and encrypted in place using the same encryption algorithm used by AvosLocker ransomware. Detection and Mitigation Opportunities Given the number of different techniques being utilized by this threat, it can be difficult to know which to prioritize for prevention and detection opportunities.
-
web:www.bleepingcomputer.com
The U.S. government has updated the list of tools AvosLocker ransomware affiliates use in attacks to include open-source utilities along with custom PowerShell, and batch scripts.
-
web:www.cisa.gov
AvosLocker affiliates compromise organizations' networks by using legitimate software and open-source remote system administration tools. AvosLocker affiliates then use exfiltration-based data extortion tactics with threats of leaking and/or publishing stolen data.
-
web:www.sentinelone.com
Understand how AvosLocker targets critical infrastructure in different countries. Prevent its spread and learn how to detect and mitigate it.
-
web:www.trendmicro.com
AvosLocker is a relatively new ransomware variant that sports the staples of modern ransomware, namely a layered extortion scheme that begins with stolen data. We shed light on this emerging ransomware family and its key techniques.
-
web:www.zscaler.com
Introduction On October 11, 2023, the Cybersecurity and Infrastructure Security Agency (CISA) published an advisory for AvosLocker , which was a sophisticated double extortion Ransomware-as-a-Service (RaaS) group that was last observed being active in May 2023. Our research team put this report together so the security community can learn how to counteract other threats that employ similar ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Reputation of linked indicators
DomScan scores the domains, AbuseIPDB + GreyNoise score the IPs. Verdicts are per-indicator — this is a roll-up, so no lookup is triggered by opening this page.
| Indicator | Type | Verdict | Score |
|---|---|---|---|
elf.avoslocker |
domain | high | 44 |