s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.gobrat

📛 Threat Title

Malware family: GobRAT

Category: GobRAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.gobrat`. Printable name: GobRAT.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.gobrat VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.gobrat

IOC database

Type
domain
Value
elf.gobrat
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.gobrat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.gobrat

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    The analysis of the router infections in Japan reveals the use of GobRAT malware and its sophisticated techniques. The findings highlight the importance of strong security measures, thorough code scrutiny, and the need for robust analysis tools to detect and mitigate the risks of similar supply chain attacks.

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as GobRAT .

  • web:blog.netmanageit.com

    The infrastructure, consisting of 63 identified servers, uses GobRAT and Bulbature malware to compromise devices and create a botnet. Features include automated exploitation, DDoS capabilities, and proxy creation. Evidence points to Chinese origin, with targeting focused on North America.

  • web:blog.sekoia.io

    Explore the investigation into the GobRAT malware and compromised edge devices transformed into ORBs to launch offensive cyberattack.

  • web:blogs.jpcert.or.jp

    In Closing In recent years, different types of malware using Go language have been confirmed, and the GobRAT malware confirmed this time uses gob, which can only be handled by Go language, for communication. Please continuously beware of malware that infects routers, not limited to GobRAT , since they are difficult to detect.

  • web:cybersecuritynews.com

    In February 2023, JPCERT/CC confirmed malware attacks on routers in Japan, specifically targeting Linux routers with a new Golang RAT known as GobRAT . The attacker exploits publicly accessible routers WEBUIs, leveraging potential vulnerabilities to infect them with the GobRAT ultimately. After an internet-exposed router is compromised, a loader script is deployed to deliver GobRAT , which ...

  • web:jstnk9.github.io

    GobRAT Loaders execute multiple discovery commands during the infection. Just to mention a few of them, next two sysmon events are related to system information discovery.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the GobRAT malware family including references, samples and yara signatures.

  • web:nsec.io

    In this talk, we will demonstrate how this small SecOps oversight allowed us to unveil a whole network of Operational Relay Boxes and a multi-layered cyber attack infrastructure involving the GobRAT malware and a previously undocumented backdoor, which we named Bulbature.

  • web:securitricks.com

    The infrastructure, consisting of 63 identified servers, uses GobRAT and Bulbature malware to compromise devices and create a botnet. Features include automated exploitation, DDoS capabilities, and proxy creation. Evidence points to Chinese origin, with targeting focused on North America.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.