s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.hellobot

📛 Threat Title

Malware family: HelloBot

Category: HelloBot First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.hellobot`. Printable name: HelloBot.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.hellobot VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.hellobot

IOC database

Type
domain
Value
elf.hellobot
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.hellobot

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.hellobot

References (1)

Remediations (9)

  • web:bazaar.abuse.ch

    Malware samples associated with tag HelloBot MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with HelloBot . Database Entry

  • web:blog.exatrack.com

    HelloBot is a malware family also targeting Linux hosts and is known to be used by APT groups such as Earth Berberoka 6. While pivoting on the Mélofée infrastructure, we found a common IP with an HelloBot sample, which provided another point to dig in.

  • web:cybersecuritynews.com

    Researchers found the malware family HelloBot , which similarly targets Linux hosts, is known to be employed by APT groups like Earth Berberoka. From at least 2020, a state-sponsored actor known as Earth Berberoka has mostly targeted gambling websites in China with multi-platform malware , including HelloBot and Pupy RAT.

  • web:hackread.com

    The group uses multi-platform malware such as Pupy RAT and HelloBot . The malware's capabilities include a kernel-mode rootkit, which is based on an open-source project called Reptile. The rootkit has limited features, as it mainly installs a hook designed to keep itself hidden.

  • web:linuxsecurity.com

    According to THN's report, the malware has also been linked to another state-sponsored APT group called Earth Berberoka (or GamblingPuppet), which mainly targets gambling websites in China and has been active since 2020. The group uses multi-platform malware such as Pupy RAT and HelloBot .

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the HelloBot malware family including references, samples and yara signatures.

  • web:securityaffairs.com

    Researchers also pointed out that the HelloBot Linux malware family , linked to Winnti APT group, shared Mélofée infrastructure. The experts also discovered another malware tracked as AlienReverse, which appears to be similar to Mélofée and includes public tools like tools EarthWorm and socks_proxy.

  • web:thehackernews.com

    The malware's ties to China come from infrastructure overlaps with groups such as APT41 (aka Winnti) and Earth Berberoka (aka GamblingPuppet). Earth Berberoka is the name given to a state-sponsored actor chiefly targeting gambling websites in China since at least 2020 using multi-platform malware like HelloBot and Pupy RAT.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.