s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.roguerobin

📛 Threat Title

Malware family: RogueRobin

Category: RogueRobin First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.roguerobin`. Printable name: RogueRobin.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain ps1.roguerobin VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ps1.roguerobin

IOC database

Type
domain
Value
ps1.roguerobin
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-ps1.roguerobin

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ps1.roguerobin

References (1)

Remediations (10)

  • web:attack.mitre.org

    RogueRobin RogueRobin is a payload used by DarkHydrus that has been developed in PowerShell and C#. [1] [2]

  • web:cve.nohackme.com

    RogueRobin is a payload used by DarkHydrus that has been developed in PowerShell and C#.

  • web:cybersecuritynews.com

    Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.

  • web:guillaumeorlando.github.io

    At the end, the malware check is a debugger is being used: This last check close the anti-analysis techniques used by the RogueRobin trojan. B) Persistence method In order to stay hidden on a compromise system, RogueRobin copy itself in the AppData folder, under the name ' OneDrive.exe '.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the RogueRobin malware family including references, samples and yara signatures.

  • web:radar.certfa.com

    A malware family known as RogueRobin , used by the DarkHydrus threat group, was discovered using DNS tunneling to covertly communicate with attackers and steal data.

  • web:redcanary.com

    Extended Berkeley Packet Filter (eBPF) is beginning to transform the Linux malware landscape. Here's what defenders should look out for.

  • web:www.fortinet.com

    FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.

  • web:www.pcrisk.com

    What is RogueRobin ? STEP 1. Manual removal of RogueRobin malware . STEP 2. Check if your computer is clean. How to remove malware manually? Manual malware removal is a complicated task - usually it is best to allow antivirus or anti- malware programs to do this automatically. To remove this malware we recommend using Combo Cleaner Antivirus for ...

  • web:www.researchgate.net

    Prevention and detection of eBPF-based malware is also explored, with the goal of providing organizations or legitimate users of eBPF techniques to harden their systems against eBPF-based malware ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.