TF-MAL-elf.rekoobe
📛 Threat Title
Malware family: Rekoobe
Description
ThreatFox malware family `elf.rekoobe`. Printable name: Rekoobe.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.rekoobe
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.rekoobe
IOC database
- Type
- domain
- Value
elf.rekoobe- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.rekoobe
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.rekoobe
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as Rekoobe .
-
web:blog.techevo.uk
In this post I will be taking a look at a Linux backdoor known as REKOOBE 1 Reporting suggests this and previous iterations have been used by APT-31 against a variety of victims.
-
web:cyberpress.org
Analysis confirmed that 555.mp5 installs the Rekoobe backdoor, a known espionage-oriented malware family . Rekoobe has historically been linked to advanced threat activity, including operations associated with APT31. According to Socket, network traffic from infected systems showed outbound communication to 154 [.]84 [.]63 [.]184 over TCP port 443. However, the traffic did not resemble standard ...
-
web:hunt.io
Discover how an open directory of Rekoobe malware samples led to different domains resembling trading platforms, posing risks for traders and investors.
-
web:malpedia.caad.fkie.fraunhofer.de
A Trojan for Linux intended to infect machines with the SPARC architecture and Intel x86, x86-64 computers. The Trojan's configuration data is stored in a file encrypted with XOR algorithm. Some versions have there configuration stored within the .data section using RC4 to encrypt the details. Configuration options include C2 IP and Port, as well as defence evasion details for changing the ...
-
web:socket.dev
That mitigation reduces exposure through Go's default module resolution path, but it does not lessen the severity of a package that impersonated a foundational Go dependency, harvested passwords, and deployed a Linux backdoor chain.
-
web:thehackernews.com
A fake Go module posing as golang.org/x/crypto captures terminal passwords, installs SSH persistence, and delivers the Rekoobe Linux backdoor.
-
web:valitrix.com
The malicious Go module impersonates a legitimate library to steal passwords. It establishes persistent access and deploys a backdoor named Rekoobe . Understanding MITRE ATT&CK techniques T1040, T1071, and T1203 is crucial for defense. Implement regular code reviews and robust network monitoring to mitigate risks. Education and awareness are essential components of cybersecurity defenses.
-
web:www.gendigital.com
Using this hardcoded file name, we extracted the file hidden by the rootkit. It is a compiled backdoor trojan written in C programming language; Avast's antivirus engine detects and classifies this file as ELF:Rekoob - which is widely known as the Rekoobe malware family . Rekoobe is a piece of code implanted in legitimate servers.
-
web:www.rescana.com
The Rekoobe backdoor is a hallmark of advanced persistent threat (APT) operations and has been previously attributed to the Chinese state-sponsored group APT31 (Zirconium). This advisory provides a comprehensive technical breakdown, threat actor profiling, exploitation evidence, victimology, and actionable mitigation strategies.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.