TF-MAL-ps1.roguerobin
📛 Threat Title
Malware family: RogueRobin
Description
ThreatFox malware family `ps1.roguerobin`. Printable name: RogueRobin.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
ps1.roguerobin
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ps1.roguerobin
IOC database
- Type
- domain
- Value
ps1.roguerobin- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-ps1.roguerobin
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ps1.roguerobin
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
RogueRobin RogueRobin is a payload used by DarkHydrus that has been developed in PowerShell and C#. [1] [2]
-
web:cve.nohackme.com
RogueRobin is a payload used by DarkHydrus that has been developed in PowerShell and C#.
-
web:cybersecuritynews.com
Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.
-
web:guillaumeorlando.github.io
At the end, the malware check is a debugger is being used: This last check close the anti-analysis techniques used by the RogueRobin trojan. B) Persistence method In order to stay hidden on a compromise system, RogueRobin copy itself in the AppData folder, under the name ' OneDrive.exe '.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the RogueRobin malware family including references, samples and yara signatures.
-
web:radar.certfa.com
A malware family known as RogueRobin , used by the DarkHydrus threat group, was discovered using DNS tunneling to covertly communicate with attackers and steal data.
-
web:redcanary.com
Extended Berkeley Packet Filter (eBPF) is beginning to transform the Linux malware landscape. Here's what defenders should look out for.
-
web:www.fortinet.com
FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.
-
web:www.pcrisk.com
What is RogueRobin ? STEP 1. Manual removal of RogueRobin malware . STEP 2. Check if your computer is clean. How to remove malware manually? Manual malware removal is a complicated task - usually it is best to allow antivirus or anti- malware programs to do this automatically. To remove this malware we recommend using Combo Cleaner Antivirus for ...
-
web:www.researchgate.net
Prevention and detection of eBPF-based malware is also explored, with the goal of providing organizations or legitimate users of eBPF techniques to harden their systems against eBPF-based malware ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.