s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.sshdinjector

📛 Threat Title

Malware family: Sshdinjector

Category: Sshdinjector First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.sshdinjector`. Printable name: Sshdinjector.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.sshdinjector VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.sshdinjector

IOC database

Type
domain
Value
elf.sshdinjector
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.sshdinjector

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.sshdinjector

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    ELF Sshdinjector is a malware family targeting SSH daemons, with samples surfacing recently as part of espionage campaigns. The malware is attributed to the DaggerFly group, also known for its involvement in the Lunar Peek campaign. These attacks focus on compromising network appliances by injecting malicious code into critical system components.

  • web:cirt.gy

    Remediation To mitigate the risk of infection from ELF/ Sshdinjector .A!tr, organizations should take the following steps: Update Security Systems: Ensure that security solutions, including antivirus and intrusion detection systems, are up to date. Fortinet customers are protected through the FortiGuard AntiVirus service.

  • web:community.gurucul.com

    "Analyzing ELF/ Sshdinjector .A!tr with a Human and Artificial Analyst" focuses on reverse engineering the ELF/ Sshdinjector .A!tr malware , which can be injected into the SSH daemon. Discovered in mid-November 2024, it is attributed to the DaggerFly espionage group and was used in the Lunar Peek campaign targeting network appliances.

  • web:gbhackers.com

    Due to Linux's dominance in cloud environments, ELF files are an ideal vector for malware seeking persistence, evasion, and widespread impact. According to the Report, Unit 42's research highlights five evolving ELF-based malware families: NoodleRAT, Winnti (Linux variants), SSHdInjector , Pygmy Goat, and AcidPour.

  • web:imtr.net

    The name " Sshdinjector " suggests its purpose involves compromising or injecting code related to the Secure Shell Daemon (sshd). ## Technical Details - Type: Malware family - Platform: ELF binaries (Linux/Unix) - Capabilities: Inferred injection into or manipulation of sshd processes.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Sshdinjector malware family including references, samples and yara signatures.

  • web:unit42.paloaltonetworks.com

    The ELF malware samples threat actors use will include backdoors, droppers, remote access Trojans (RATs), data wipers and vulnerability-exploiting binaries. During our investigation, we focused on five ELF-based malware families, each of which threat actor groups have used to target cloud environments during their operations.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.cybersecurity-review.com

    ELF/ Sshdinjector .A!tr is a collection of malware that can be injected into the SSH daemon. Samples of this malware collection surfaced around mid-November 2024.

  • web:www.fortinet.com

    Fortinet Protections Fortinet customers are already protected from this malware variant through our AntiVirus as follows: FortiGuard Labs detects the sample with the following AV signatures: ELF/ Sshdinjector .A !tr and Linux/Agent.ACQ!tr The FortiGuard AntiVirus service is supported by FortiGate, FortiMail, FortiClient, and FortiEDR.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.