s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.denonia

📛 Threat Title

Malware family: Denonia

Category: Denonia First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.denonia`. Printable name: Denonia.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.denonia VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.denonia

IOC database

Type
domain
Value
elf.denonia
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.denonia

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.denonia

References (1)

Remediations (10)

  • web:blog.qualys.com

    The data show the bulk of malware that will impact an insecure cloud asset is some variant of the crypto miner, many of which are generic and a few of which have received names — like Denonia . Denonia Denonia malware is an exciting use case as it is the first malware strain to specifically target AWS Lambda.

  • web:imtr.net

    # Tool/Technique: Denonia /XMRig Campaign ## Overview Denonia is a newly discovered type of malware specifically designed to target and infect AWS Lambda serverless environments. Its primary purpose is resource hijacking through the deployment of the XMRig cryptominer to illicitly mine Monero cryptocurrency.

  • web:malpedia.caad.fkie.fraunhofer.de

    Cado discovered this malware , written in Go and targeting AWS Lambda environments.

  • web:nordvpn.com

    Learn about Denonia cryptominer, its impact on AWS Lambda and Linux, infection methods, and protection steps to secure your cloud resources from this threat.

  • web:support.trellix.com

    Summary Description of Campaign The Denonia malware family was discovered to attack AWS Lambda environments. This malware is written in the Go programming language and contains a customized version of the XMRig mining software. Denonia uses DNS over HTTPS (DoH) to avoid detection and communicate with actor-controlled C2 servers.

  • web:threats.wiz.io

    https://www.cadosecurity.com/cado-discovers- denonia -the-first- malware -specifically-targeting-lambda/

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.cy5.io

    Denonia , is a cloud first malware that targets Lambda functions. Read about it's behaviour and means to prevent & detect it at cloud scale.

  • web:www.quorumcyber.com

    A new malware strain, dubbed Denonia , has been seen targeting AWS Lambda cloud environments. Written in Go, it contains a variant of the XMRig crypto mining software and some other functions.

  • web:www.sentinelone.com

    How Did Denonia Malware Exploit Complex Cloud Infrastructure? According to the Cado Labs research report, Denonia malware is the first of its kind designed specifically to target the AWS Lambda environment. The malware takes its name from the domain ' gw. denonia .xyz ' that it communicates with.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.