s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.qilin

📛 Threat Title

Malware family: Qilin

Category: Qilin First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.qilin`. Printable name: Qilin.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.qilin VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.qilin

IOC database

Type
domain
Value
elf.qilin
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.qilin

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.qilin

References (1)

Remediations (10)

  • web:attack.mitre.org

    Qilin is a ransomware family operated as a ransomware-as-a-service (RaaS) that has been active since at least 2022. It includes variants written in Go and Rust capable of targeting Windows, Linux, and VMware ESXi environments. Qilin shares functionality overlaps with Black Basta, REvil, and BlackCat ransomware. Qilin affiliates have targeted multiple entities worldwide with the majority of ...

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as Qilin .

  • web:blackpointcyber.com

    Qilin.B uses RSA-4096 with Optimal Asymmetric Encryption Padding (OAEP) to safeguard encryption keys. Qilin.B was updated with new defense evasion techniques as well. Qilin.B still terminates services associated with security tools, clears Windows Event Logs, but also deletes itself to reduce indication that the malware was there.

  • web:cybelangel.com

    How Qilin ransomware operates, initial access, double extortion, recent victims including Die Linke, and what you need to detect and stop it.

  • web:cybersecuritynews.com

    Qilin ransomware group is deploying a sophisticated, multi-stage infection chain via a malicious msimg32.dll that can disable over 300 endpoint detection and response (EDR) drivers from virtually every major security vendor.

  • web:dailysecurityreview.com

    Qilin ransomware, a potent threat emerging in 2022, has rapidly gained notoriety. This blog post delves into its advanced tactics, techniques, and procedures (TTPs), providing crucial insights into its operational evolution, attack methods, and effective defense strategies. Discover how to protect your systems from this dangerous malware .

  • web:www.dexpose.io

    Complete guide to the Qilin ransomware group, attack history, TTPs, IOCs, MITRE mapping, Chrome credential theft, WSL exploits, and how to detect exposure before ransom hits.

  • web:www.linkedin.com

    First observed in July 2022, Qilin initially utilized ransomware written in the Go programming language. By December 2022, the group had transitioned to Rust-based malware , enhancing its cross ...

  • web:www.malwarebytes.com

    Click Quarantine to remove the found threats. Business remediation How to remove Ransom. Qilin with the Malwarebytes Nebula console You can use the Malwarebytes Anti- Malware Nebula console to scan endpoints. Nebula endpoint tasks menu Choose the Scan + Quarantine option. Afterwards you can check the Detections page to see which threats were found.

  • web:www.picussecurity.com

    This combination of token manipulation and symbolic link exploitation enhances the ransomware's ability to operate stealthily and extend its reach across networked environments, making detection and mitigation more challenging. TA0005: Defense Evasion T1070 Indicator Removal As part of its defense evasion strategy, the Qilin ransomware employs a multi-phase approach to eliminate forensic ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.