TF-MAL-elf.bashlite
📛 Threat Title
Malware family: Bashlite
Description
ThreatFox malware family `elf.bashlite`. Printable name: Bashlite. Aliases: gayfgt,Gafgyt,qbot,torlus,lizkebab.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.bashlite
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bashlite
IOC database
- Type
- domain
- Value
elf.bashlite- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.bashlite
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bashlite
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:any.run
What is Gafgyt malware ? Gafgyt, also known as BASHLITE , LizardStresser, and Torlus, is a malware family that targets Linux-based IoT devices such as routers and IP cameras. It is known for its botnet capabilities, which allow it to conduct DDoS attacks and perform other malicious activities.
-
web:en.wikipedia.org
BASHLITE (also known as Gafgyt, Lizkebab, PinkSlip, Qbot, Torlus and LizardStresser) is malware which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). [1]
-
web:github.com
Malware source code samples leaked online uploaded to GitHub for those who want to analyze the code - ifding/iot- malware
-
web:hunt.io
Gafgyt (also known as Bashlite ) is a type of malware that targets Internet of Things (IoT) devices. First seen in 2014 it compromises routers and IP cameras to form botnets used for DDoS attacks. Over time Gafgyt has evolved and expanded to include cloud environments and Docker platforms.
-
web:malpedia.caad.fkie.fraunhofer.de
Bashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware . It has been used to launch attacks of up to 400 Gbps.
-
web:medium.com
This analysis breaks down a variant of the Gafgyt (a.k.a. Bashlite ) malware family . This lightweight botnet connects to a hardcoded C2, launches Telnet brute-force attacks, and executes arbitrary ...
-
web:rewterz.com
Organizations should be aware of the threat posed by Gafgyt malware and take appropriate measures to protect their networks from DDoS attacks, such as implementing DDoS mitigation solutions.
-
web:securityscorecard.com
Executive summary geted millions of vulnerable IoT devices in the last few years. The recently compiled sample we've nalyzed borrowed some code leaked online from the Mirai botnet. The following commands are implemented: ALPHA, GAME, GRE, ICMP, JAIL, KICK, MIX, PLAIN, QUERY, SPEC, and STOP. The purpose of these commands is to perform multiple types of TCP and UDP DoS attacks, to target game ...
-
web:srcdi.uob.edu.bh
Malware , a type of malicious software [4], plays a crucial role in these attacks. Notably, the Bashlite and Mirai malware have been among the most dangerous in recent years, even being responsible for the largest recorded DDoS attack [5].
-
web:www.huntress.com
The creators of Bashlite remain anonymous, though early analysis suggests it originated as part of underground cybercrime operations. The open availability of its source code has allowed multiple threat actors to modify and repurpose the malware for various malicious goals.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.