s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.seaspy

📛 Threat Title

Malware family: SEASPY

Category: SEASPY First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.seaspy`. Printable name: SEASPY.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.seaspy VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.seaspy

IOC database

Type
domain
Value
elf.seaspy
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.seaspy

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.seaspy

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    Additionally, Barracuda had found SeaSpy , a persistent passive backdoor, on compromised ESG appliances. SeaSpy operated under the guise of a legitimate service and executed commands on behalf of threat actors. Attacker campaign targeting Barracuda Email Security Gateway devices, critical vulnerabilities, and a range of sophisticated malware .

  • web:bazaar.abuse.ch

    Malware samples associated with tag seaspy MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with seaspy . Database Entry

  • web:blog.netmanageit.com

    Description CISA obtained two SEASPY malware samples. The malware was used by threat actors exploiting CVE-2023-2868, a former zero-day vulnerability afecting versions 5.1.3.001-9.2.0.006 of Barracuda Email Security Gateway (ESG). SEASPY is a persistent and passive backdoor that masquerades as a legitimate Barracuda service "BarracudaMailService" that allows the threat actors to execute ...

  • web:malpedia.caad.fkie.fraunhofer.de

    The malware is designed to listen to commands received from the Threat Actor's Command-and-Control through TCP packets. When executed, the malware uses libpcap sniffer to monitor traffic for a magic packet on TCP port 25 (SMTP) and TCP port 587.

  • web:stardm.net

    Description CISA obtained two SEASPY malware samples. The malware was used by threat actors exploiting CVE-2023-2868, a former zero-day vulnerability affecting versions 5.1.3.001-9.2.0.006 of Barracuda Email Security Gateway (ESG).

  • web:www.cisa.gov

    A Malware Initial Findings Report (MIFR) is intended to provide organizations with malware analysis in a timely manner. In most instances this report will provide initial indicators for computer and network defense.

  • web:www.scribd.com

    SEASPY acts as a persistent backdoor, while WHIRLPOOL establishes a TLS reverse shell to a Command-and-Control server. The report includes technical details about the malware samples and their behavior, emphasizing the need for awareness and mitigation strategies against such threats.

  • web:www.securityweek.com

    Identified malware families include the SeaSpy , SaltWater, and SeaSide custom backdoors, the SandBar rootkit, and SeaSpray and SkipJack, which are trojanized versions of legitimate Barracuda Lua modules. The observed attacks targeted victims in at least 16 different countries, including government officials and high-profile academics.

  • web:www.spamtitan.com

    A zero-day vulnerability in Barracuda email security gateway (ESG) appliances was exploited to deliver three malware variants onto the devices. These previously unknown malware variants have been dubbed SeaSide, Saltwater, and Seaspy , with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently reporting that an additional malware backdoor dubbed Submarine was also deployed ...

  • web:www.threatdown.com

    The report discusses seven malware samples obtained by CISA and the contents of the compromised SQL database, which included sensitive information. According to Barracuda, the SUBMARINE malware was utilized by the threat actor in response to Barracuda's remediation actions in an attempt to create persistent access on customer ESG appliances.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.