TF-MAL-elf.gobrat
📛 Threat Title
Malware family: GobRAT
Description
ThreatFox malware family `elf.gobrat`. Printable name: GobRAT.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.gobrat
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.gobrat
IOC database
- Type
- domain
- Value
elf.gobrat- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.gobrat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.gobrat
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
The analysis of the router infections in Japan reveals the use of GobRAT malware and its sophisticated techniques. The findings highlight the importance of strong security measures, thorough code scrutiny, and the need for robust analysis tools to detect and mitigate the risks of similar supply chain attacks.
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as GobRAT .
-
web:blog.netmanageit.com
The infrastructure, consisting of 63 identified servers, uses GobRAT and Bulbature malware to compromise devices and create a botnet. Features include automated exploitation, DDoS capabilities, and proxy creation. Evidence points to Chinese origin, with targeting focused on North America.
-
web:blog.sekoia.io
Explore the investigation into the GobRAT malware and compromised edge devices transformed into ORBs to launch offensive cyberattack.
-
web:blogs.jpcert.or.jp
In Closing In recent years, different types of malware using Go language have been confirmed, and the GobRAT malware confirmed this time uses gob, which can only be handled by Go language, for communication. Please continuously beware of malware that infects routers, not limited to GobRAT , since they are difficult to detect.
-
web:cybersecuritynews.com
In February 2023, JPCERT/CC confirmed malware attacks on routers in Japan, specifically targeting Linux routers with a new Golang RAT known as GobRAT . The attacker exploits publicly accessible routers WEBUIs, leveraging potential vulnerabilities to infect them with the GobRAT ultimately. After an internet-exposed router is compromised, a loader script is deployed to deliver GobRAT , which ...
-
web:jstnk9.github.io
GobRAT Loaders execute multiple discovery commands during the infection. Just to mention a few of them, next two sysmon events are related to system information discovery.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the GobRAT malware family including references, samples and yara signatures.
-
web:nsec.io
In this talk, we will demonstrate how this small SecOps oversight allowed us to unveil a whole network of Operational Relay Boxes and a multi-layered cyber attack infrastructure involving the GobRAT malware and a previously undocumented backdoor, which we named Bulbature.
-
web:securitricks.com
The infrastructure, consisting of 63 identified servers, uses GobRAT and Bulbature malware to compromise devices and create a botnet. Features include automated exploitation, DDoS capabilities, and proxy creation. Evidence points to Chinese origin, with targeting focused on North America.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.