s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.goreverse

📛 Threat Title

Malware family: GOREVERSE

Category: GOREVERSE First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.goreverse`. Printable name: GOREVERSE.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.goreverse VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.goreverse

IOC database

Type
domain
Value
elf.goreverse
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.goreverse

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.goreverse

References (1)

Remediations (10)

  • web:cloud.google.com

    After backdoor accounts were configured, they attempted to self-patch the vulnerability using an F5-provided mitigation script " mitigation .sh ". Mandiant assesses that this was an attempt to limit subsequent exploitation of the system by additional unrelated threat actors attempting to access the appliance.

  • web:github.com

    \n","renderedFileInfo":null,"shortPath":null,"tabSize":8,"topBannersInfo":{"overridingGlobalFundingFile":false,"globalPreferredFundingPath":null,"repoOwner":"JvPy ...

  • web:malpedia.caad.fkie.fraunhofer.de

    GOREVERSE is a publicly available reverse shell backdoor written in GoLang that operates over Secure Shell (SSH).

  • web:rhisac.org

    Mandiant provided the following detections: rule M_Backdoor_GOREVERSE_2 { meta: author = "Mandiant" description = "This rule is designed to detect events related to goreverse . GOREVERSE is a publicly available reverse shell" md5 = "5c175ea3664279d6c0c2609844de6949" platforms = "Windows,Linux,MacOS" malware_family = " GOREVERSE ...

  • web:securityonline.info

    Threat Actors Exploit GeoServer Vulnerability CVE-2024-36401 to Launch Malware Campaigns Cybersecurity researchers at FortiGuard Labs have observed multiple campaigns targeting a critical vulnerability in GeoServer, an open-source geospatial data server.

  • web:www.bankinfosecurity.com

    Once deployed, Goreverse establishes a connection with a command-and-control server, enabling attackers to control the compromised system and execute further malicious actions.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.hivepro.com

    Malware : SNOWLIGHT, GOHEAVY, GOREVERSE , and SUPERSHELL Attack: UNC5174, a threat actor believed to be associated with China, has been identified exploiting various vulnerabilities and deploying custom tools such as SNOWLIGHT, GOHEAVY, and GOREVERSE for post-exploitation activities.

  • web:www.redpacketsecurity.com

    The Shadowserver Foundation said it detected exploitation attempts against its honeypot sensors starting July 9, 2024. According to Fortinet FortiGuard Labs, the flaw has been observed to deliver GOREVERSE , a reverse proxy server designed to establish a connection with a command-and-control (C2) server for post-exploitation activity.

  • web:www.technewscentre.com

    Fortinet's FortiGuard Labs has reported that the flaw is being used to deploy GOREVERSE , a reverse proxy server that establishes a link with a command-and-control (C2) server, enabling further malicious actions.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.