TF-MAL-elf.sshdinjector
📛 Threat Title
Malware family: Sshdinjector
Description
ThreatFox malware family `elf.sshdinjector`. Printable name: Sshdinjector.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.sshdinjector
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.sshdinjector
IOC database
- Type
- domain
- Value
elf.sshdinjector- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.sshdinjector
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.sshdinjector
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
ELF Sshdinjector is a malware family targeting SSH daemons, with samples surfacing recently as part of espionage campaigns. The malware is attributed to the DaggerFly group, also known for its involvement in the Lunar Peek campaign. These attacks focus on compromising network appliances by injecting malicious code into critical system components.
-
web:cirt.gy
Remediation To mitigate the risk of infection from ELF/ Sshdinjector .A!tr, organizations should take the following steps: Update Security Systems: Ensure that security solutions, including antivirus and intrusion detection systems, are up to date. Fortinet customers are protected through the FortiGuard AntiVirus service.
-
web:community.gurucul.com
"Analyzing ELF/ Sshdinjector .A!tr with a Human and Artificial Analyst" focuses on reverse engineering the ELF/ Sshdinjector .A!tr malware , which can be injected into the SSH daemon. Discovered in mid-November 2024, it is attributed to the DaggerFly espionage group and was used in the Lunar Peek campaign targeting network appliances.
-
web:gbhackers.com
Due to Linux's dominance in cloud environments, ELF files are an ideal vector for malware seeking persistence, evasion, and widespread impact. According to the Report, Unit 42's research highlights five evolving ELF-based malware families: NoodleRAT, Winnti (Linux variants), SSHdInjector , Pygmy Goat, and AcidPour.
-
web:imtr.net
The name " Sshdinjector " suggests its purpose involves compromising or injecting code related to the Secure Shell Daemon (sshd). ## Technical Details - Type: Malware family - Platform: ELF binaries (Linux/Unix) - Capabilities: Inferred injection into or manipulation of sshd processes.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Sshdinjector malware family including references, samples and yara signatures.
-
web:unit42.paloaltonetworks.com
The ELF malware samples threat actors use will include backdoors, droppers, remote access Trojans (RATs), data wipers and vulnerability-exploiting binaries. During our investigation, we focused on five ELF-based malware families, each of which threat actor groups have used to target cloud environments during their operations.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.cybersecurity-review.com
ELF/ Sshdinjector .A!tr is a collection of malware that can be injected into the SSH daemon. Samples of this malware collection surfaced around mid-November 2024.
-
web:www.fortinet.com
Fortinet Protections Fortinet customers are already protected from this malware variant through our AntiVirus as follows: FortiGuard Labs detects the sample with the following AV signatures: ELF/ Sshdinjector .A !tr and Linux/Agent.ACQ!tr The FortiGuard AntiVirus service is supported by FortiGate, FortiMail, FortiClient, and FortiEDR.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.