s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.darkside

📛 Threat Title

Malware family: DarkSide

Category: DarkSide First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.darkside`. Printable name: DarkSide.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.darkside VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.darkside

IOC database

Type
domain
Value
elf.darkside
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.darkside

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.darkside

References (1)

Remediations (10)

  • web:7orvs.github.io

    DarkSide 14 minute read On this page Dark-Side Ransomware Analysis Overview Initial View Advanced Analysis Getting information about the process Run-Time API resolving Configration Decoding Check the system's default language Generate encrypted extension Privilege Escalation (UAC Bypass) Conclusion References: Dark-Side Ransomware Analysis Overview DarkSide is believed to be based in Eastern ...

  • web:brandefense.io

    The DarkSide threat group also has been using the Double Extortion attack model. It is standardized between ransomware gangs to enforce organizations that have disaster recovery plans and refuse to pay the ransom. Therefore, if the victim accomplishes to recover encrypted data, they still have to pay to avoid publicly sharing data.

  • web:cloud.google.com

    The creators of DARKSIDE ransomware have launched a global crime spree affecting organizations in more than 15 countries and multiple industry verticals.

  • web:en.wikipedia.org

    DarkSide is a cybercriminal hacking group, believed to be based in Russia, that targets victims using ransomware and extortion; it is believed to be behind the Colonial Pipeline cyberattack. [1][2][3][4] The group provides ransomware as a service. [4][5][6]

  • web:knowledgebase.paloaltonetworks.com

    Question What is the DarkSide ransomware and what are the best mitigation and prevention steps? Environment All PAN-OS Anti-Virus license Answer What is DarkSide ransomware? DarkSide ransomware was first seen in August 2020 on Russian language hacking forums. It is a ransomware-as-a-service platform that cybercriminals can hire.

  • web:malpedia.caad.fkie.fraunhofer.de

    FireEye describes DARKSIDE as a ransomware written in C and configurable to target files whether on fixed, removable disks, or network shares. The malware can be customized by the affiliates to create a build for specific victims.

  • web:success.trendmicro.com

    Darkside , which is being offered via the ransomware-as-a-service (RaaS) model, has already been deployed against critical infrastructure in the United States. It uses a "double extortion" technique where the attackers threaten to release sensitive information in addition to encrypting data on their victim's machines.

  • web:www.cisa.gov

    The malware collects, encrypts, and sends system information to the threat actor's command and control (C2) domains and generates a ransom note to the victim. For more information about this variant, refer to Malware Analysis Report MAR-10337802-1.v1: DarkSide Ransomware. Click here for a PDF version of this report.

  • web:www.fortinet.com

    DarkSide ransomware represents a sophisticated criminal enterprise that operates as a service-based business model. It's called ransomware as a service (RaaS). The malware uses Salsa20 stream cipher combined with RSA public key cryptography to encrypt victim files. Then, attackers threaten to publicly release stolen information if ransoms are not paid. Each infected system gets a unique 8 ...

  • web:www.picussecurity.com

    In this research, we investigated Tactics, Techniques, and Procedures (TTPs) and tools utilized by the Darkside ransomware threat group.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.