TF-MAL-osx.eleanor
📛 Threat Title
Malware family: Eleanor
Description
ThreatFox malware family `osx.eleanor`. Printable name: Eleanor.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.eleanor
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.eleanor
IOC database
- Type
- domain
- Value
osx.eleanor- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.eleanor
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.eleanor
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:macos.checkpoint.com
Eleanor is a bundle of several open source applications and scripts. Eleanor acts as an "EasyDoc Converter" app which purports to convert file formats into Microsoft Word files, but actually this malware opens a back door into Mac OS X systems via the Tor network.
-
web:malpedia.caad.fkie.fraunhofer.de
Eleanor comes as a drag-and-drop file utility called EasyDoc Converter. This application bundle wraps a shell script that uses Dropbox name as a disguise and installs three components: a hidden Tor service, a Pastebin agent and a web service with a PHP-based graphical interface. The Tor service transforms the victim's computer into a server that provides attackers with full anonymous access ...
-
web:www.breachsense.com
Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.cloudhesive.com
The illusion of perfect security entertained by many Apple users gets easily shattered when a new bug appears on the horizon. Eleanor is the latest of these OS-specific malware applications; it opens a backdoor into the computer it infects, allowing total control of the system through a hidden Tor service, a PasteBin client and a PHP Web Service.
-
web:www.enigmasoftware.com
OSX/ Eleanor is a threat designed to attack computers running the Mac OSX. OSX/ Eleanor has been active since at least Summer of 2016. The OSX/ Eleanor attacks in the past, have been associated with bogus software downloads, such as a file converter application. Malware researchers received reports of the EasyDoc Converter, supposedly a program designed to help computer users convert file types ...
-
web:www.interplayit.com
New OS X Malware : How To Protect Your Mac From Eleanor While Apple malware isn't unheard of, it is less often found in the wild. The illusion of perfect security entertained by many Apple users gets easily shattered when a new bug appears on the horizon.
-
web:www.linkedin.com
Researchers have spotted a new type of malware that uses the Tor anonymizing service to obtain full access to an infected Mac system.
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
-
web:www.pcrisk.com
If your computer is already infected with malware , we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate them. EasyDoc Converter used to distribute (install) Eleanor malware : Instant automatic malware removal: Manual threat removal might be a lengthy and complicated process that requires advanced IT skills.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.