s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.wellmail

📛 Threat Title

Malware family: WellMail

Category: WellMail First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.wellmail`. Printable name: WellMail.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.wellmail VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.wellmail

IOC database

Type
domain
Value
elf.wellmail
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.wellmail

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.wellmail

References (1)

Remediations (10)

  • web:apt.etda.or.th

    Last change to this tool card: 30 December 2022 Download this tool card in JSON format All groups using tool WellMail

  • web:attack.mitre.org

    WellMail WellMail is a lightweight malware written in Golang used by APT29, similar in design and structure to WellMess. [1] [2]

  • web:consumer.ftc.gov

    Malware is one of the biggest threats to the security of your computer, tablet, phone, and other devices. Learn how to protect yourself, how to tell if your device has malware , and how to remove it.

  • web:kcm.trellix.com

    Active infrastructure believed to be associated with the Russian threat actor APT29 and used to deliver malware tracked as WellMail and WellMess was identified in a report released on July 30, 2021. The research, performed by RiskIQ, identified SSL certificates, IP addresses, and associated domain names belonging to C2 servers.

  • web:learn.microsoft.com

    Manual and automated remediation Manual hunting occurs when security teams identify threats manually by using the search and filtering capabilities in Explorer (Threat Explorer). Manual email remediation can be triggered through any email view ( Malware , Phish, or All email) after you identify a set of emails that need to be remediated.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the WellMail malware family including references, samples and yara signatures.

  • web:openhunting.io

    The NCSC has named this malware 'WellMail' due to file paths containing the word 'mail' and the use of server port 25 present in the sample analysed. Similar to { {WellMess}}, WellMail uses hard-coded client and certificate authority TLS certificates to communicate with C2 servers.

  • web:www.breachsense.com

    Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.

  • web:www.cisa.gov

    Overview Cyber-attacks can come in many forms. Malware , Phishing, and Ransomware are becoming increasingly common forms of attack and can affect individuals and large organizations. Malware is any software used to gain unauthorized access to IT systems in order to steal data, disrupt system services or damage IT networks in any way. Ransomware is a type of malware identified by specified data ...

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.