TF-MAL-elf.denonia
📛 Threat Title
Malware family: Denonia
Description
ThreatFox malware family `elf.denonia`. Printable name: Denonia.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.denonia
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.denonia
IOC database
- Type
- domain
- Value
elf.denonia- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.denonia
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.denonia
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.qualys.com
The data show the bulk of malware that will impact an insecure cloud asset is some variant of the crypto miner, many of which are generic and a few of which have received names — like Denonia . Denonia Denonia malware is an exciting use case as it is the first malware strain to specifically target AWS Lambda.
-
web:imtr.net
# Tool/Technique: Denonia /XMRig Campaign ## Overview Denonia is a newly discovered type of malware specifically designed to target and infect AWS Lambda serverless environments. Its primary purpose is resource hijacking through the deployment of the XMRig cryptominer to illicitly mine Monero cryptocurrency.
-
web:malpedia.caad.fkie.fraunhofer.de
Cado discovered this malware , written in Go and targeting AWS Lambda environments.
-
web:nordvpn.com
Learn about Denonia cryptominer, its impact on AWS Lambda and Linux, infection methods, and protection steps to secure your cloud resources from this threat.
-
web:support.trellix.com
Summary Description of Campaign The Denonia malware family was discovered to attack AWS Lambda environments. This malware is written in the Go programming language and contains a customized version of the XMRig mining software. Denonia uses DNS over HTTPS (DoH) to avoid detection and communicate with actor-controlled C2 servers.
-
web:threats.wiz.io
https://www.cadosecurity.com/cado-discovers- denonia -the-first- malware -specifically-targeting-lambda/
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.cy5.io
Denonia , is a cloud first malware that targets Lambda functions. Read about it's behaviour and means to prevent & detect it at cloud scale.
-
web:www.quorumcyber.com
A new malware strain, dubbed Denonia , has been seen targeting AWS Lambda cloud environments. Written in Go, it contains a variant of the XMRig crypto mining software and some other functions.
-
web:www.sentinelone.com
How Did Denonia Malware Exploit Complex Cloud Infrastructure? According to the Cado Labs research report, Denonia malware is the first of its kind designed specifically to target the AWS Lambda environment. The malware takes its name from the domain ' gw. denonia .xyz ' that it communicates with.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.