TF-MAL-elf.darkside
📛 Threat Title
Malware family: DarkSide
Description
ThreatFox malware family `elf.darkside`. Printable name: DarkSide.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.darkside
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.darkside
IOC database
- Type
- domain
- Value
elf.darkside- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.darkside
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.darkside
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:7orvs.github.io
DarkSide 14 minute read On this page Dark-Side Ransomware Analysis Overview Initial View Advanced Analysis Getting information about the process Run-Time API resolving Configration Decoding Check the system's default language Generate encrypted extension Privilege Escalation (UAC Bypass) Conclusion References: Dark-Side Ransomware Analysis Overview DarkSide is believed to be based in Eastern ...
-
web:brandefense.io
The DarkSide threat group also has been using the Double Extortion attack model. It is standardized between ransomware gangs to enforce organizations that have disaster recovery plans and refuse to pay the ransom. Therefore, if the victim accomplishes to recover encrypted data, they still have to pay to avoid publicly sharing data.
-
web:cloud.google.com
The creators of DARKSIDE ransomware have launched a global crime spree affecting organizations in more than 15 countries and multiple industry verticals.
-
web:en.wikipedia.org
DarkSide is a cybercriminal hacking group, believed to be based in Russia, that targets victims using ransomware and extortion; it is believed to be behind the Colonial Pipeline cyberattack. [1][2][3][4] The group provides ransomware as a service. [4][5][6]
-
web:knowledgebase.paloaltonetworks.com
Question What is the DarkSide ransomware and what are the best mitigation and prevention steps? Environment All PAN-OS Anti-Virus license Answer What is DarkSide ransomware? DarkSide ransomware was first seen in August 2020 on Russian language hacking forums. It is a ransomware-as-a-service platform that cybercriminals can hire.
-
web:malpedia.caad.fkie.fraunhofer.de
FireEye describes DARKSIDE as a ransomware written in C and configurable to target files whether on fixed, removable disks, or network shares. The malware can be customized by the affiliates to create a build for specific victims.
-
web:success.trendmicro.com
Darkside , which is being offered via the ransomware-as-a-service (RaaS) model, has already been deployed against critical infrastructure in the United States. It uses a "double extortion" technique where the attackers threaten to release sensitive information in addition to encrypting data on their victim's machines.
-
web:www.cisa.gov
The malware collects, encrypts, and sends system information to the threat actor's command and control (C2) domains and generates a ransom note to the victim. For more information about this variant, refer to Malware Analysis Report MAR-10337802-1.v1: DarkSide Ransomware. Click here for a PDF version of this report.
-
web:www.fortinet.com
DarkSide ransomware represents a sophisticated criminal enterprise that operates as a service-based business model. It's called ransomware as a service (RaaS). The malware uses Salsa20 stream cipher combined with RSA public key cryptography to encrypt victim files. Then, attackers threaten to publicly release stolen information if ransoms are not paid. Each infected system gets a unique 8 ...
-
web:www.picussecurity.com
In this research, we investigated Tactics, Techniques, and Procedures (TTPs) and tools utilized by the Darkside ransomware threat group.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.