s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.rekoobe

📛 Threat Title

Malware family: Rekoobe

Category: Rekoobe First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.rekoobe`. Printable name: Rekoobe.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.rekoobe VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.rekoobe

IOC database

Type
domain
Value
elf.rekoobe
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.rekoobe

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.rekoobe

References (1)

Remediations (10)

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as Rekoobe .

  • web:blog.techevo.uk

    In this post I will be taking a look at a Linux backdoor known as REKOOBE 1 Reporting suggests this and previous iterations have been used by APT-31 against a variety of victims.

  • web:cyberpress.org

    Analysis confirmed that 555.mp5 installs the Rekoobe backdoor, a known espionage-oriented malware family . Rekoobe has historically been linked to advanced threat activity, including operations associated with APT31. According to Socket, network traffic from infected systems showed outbound communication to 154 [.]84 [.]63 [.]184 over TCP port 443. However, the traffic did not resemble standard ...

  • web:hunt.io

    Discover how an open directory of Rekoobe malware samples led to different domains resembling trading platforms, posing risks for traders and investors.

  • web:malpedia.caad.fkie.fraunhofer.de

    A Trojan for Linux intended to infect machines with the SPARC architecture and Intel x86, x86-64 computers. The Trojan's configuration data is stored in a file encrypted with XOR algorithm. Some versions have there configuration stored within the .data section using RC4 to encrypt the details. Configuration options include C2 IP and Port, as well as defence evasion details for changing the ...

  • web:socket.dev

    That mitigation reduces exposure through Go's default module resolution path, but it does not lessen the severity of a package that impersonated a foundational Go dependency, harvested passwords, and deployed a Linux backdoor chain.

  • web:thehackernews.com

    A fake Go module posing as golang.org/x/crypto captures terminal passwords, installs SSH persistence, and delivers the Rekoobe Linux backdoor.

  • web:valitrix.com

    The malicious Go module impersonates a legitimate library to steal passwords. It establishes persistent access and deploys a backdoor named Rekoobe . Understanding MITRE ATT&CK techniques T1040, T1071, and T1203 is crucial for defense. Implement regular code reviews and robust network monitoring to mitigate risks. Education and awareness are essential components of cybersecurity defenses.

  • web:www.gendigital.com

    Using this hardcoded file name, we extracted the file hidden by the rootkit. It is a compiled backdoor trojan written in C programming language; Avast's antivirus engine detects and classifies this file as ELF:Rekoob - which is widely known as the Rekoobe malware family . Rekoobe is a piece of code implanted in legitimate servers.

  • web:www.rescana.com

    The Rekoobe backdoor is a hallmark of advanced persistent threat (APT) operations and has been previously attributed to the Chinese state-sponsored group APT31 (Zirconium). This advisory provides a comprehensive technical breakdown, threat actor profiling, exploitation evidence, victimology, and actionable mitigation strategies.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.