s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.satori

📛 Threat Title

Malware family: Satori

Category: Satori First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.satori`. Printable name: Satori.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.satori VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.satori

IOC database

Type
domain
Value
elf.satori
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.satori

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.satori

References (1)

Remediations (10)

  • web:arxiv.org

    A. Satori Satori was a Mirai variant initially active between 2017 and 2018. In December 2017, Satori infected over 280,000 IoT devices within 12 hours of its activation [27].

  • web:malpedia.caad.fkie.fraunhofer.de

    Satori is a variation of elf.mirai which was first detected around 2017-11-27 by 360 Netlab. It uses exploit to exhibit worm-like behaviour to spread over ports 37215 and 52869 (CVE-2014-8361).

  • web:unit42.paloaltonetworks.com

    We observed attempts to spread Satori , a Mirai botnet variant, by exploitig CVE-2020-9020, an RCE vulnerability targeting Vantage Velocity.

  • web:www.humansecurity.com

    HUMAN's Satori Threat Intelligence and Research Team uncovered BADBOX 2.0, a major expansion and adaptation of the earlier BADBOX operation.

  • web:www.joesandbox.com

    The malware initially executes as ` satori .exe` from the user's Desktop directory (PID 8172). A second instance of the same executable also runs (PID 3800), indicating potential multiple execution paths or persistence activation.

  • web:www.malwarebytes.com

    The BSI said it found: "The BadBox malware was already installed on the respective devices when they were purchased." According to Satori Threat Intelligence researchers: "Devices connected to the BADBOX 2.0 operation included lower-price-point, "off brand", uncertified tablets, connected TV (CTV) boxes, digital projectors, and more.

  • web:www.netscout.com

    Furthermore, now that this new ground has been broken, it paves the way for other malware authors to target that architecture. DDoS Mitigation Since the variants of Satori all leverage different subsets of the Mirai DDoS attack codebase, longstanding Mirai-based DDoS mitigation advice still applies.

  • web:www.quorumcyber.com

    Mirai is a botnet malware variant that compromises smart devices that operate on ARC processors, the aim of which is to formulate a network of bot machines to carry out distributed denial-of-service (DDoS) attacks1.

  • web:www.sciencedirect.com

    In November 2017, a new variant of Mirai named Satori emerged, whose peculiarity lies in the way the malware is spread, making it more worm-like [45]. The bot, in fact, does not rely on the loader-scanner mechanism to perform remote planting [46].

  • web:www.semanticscholar.org

    This article summarizes the common vulnerabilities targeted by these variants and analyzes the infection mechanism through vulnerability analysis and provides an overview of possible defense solutions. Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.