TF-MAL-elf.wellmess
📛 Threat Title
Malware family: elf.wellmess
Description
ThreatFox malware family `elf.wellmess`.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.wellmess
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.wellmess
IOC database
- Type
- domain
- Value
elf.wellmess- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.wellmess
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.wellmess
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:apt.etda.or.th
Last change to this tool card: 30 December 2022 Download this tool card in JSON format All groups using tool WellMess
-
web:apt.securelist.com
WellMess is a Remote Access Trojan that has been deployed against high-profile targets in MENA and the EU, as well as companies conducting COVID-19 vaccine research.
-
web:attack.mitre.org
WellMess is lightweight malware family with variants written in .NET and Golang that has been in use since at least 2018 by APT29. [1] [2] [3]
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as WellMess.
-
web:iopscience.iop.org
By understanding these structural differences between malicious and benign ELF files, security analysts can develop more effective detection and mitigation strategies to safeguard systems against evolving malware threats.
-
web:learn.microsoft.com
Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the elf.wellmess malware family including references, samples and yara signatures.
-
web:openhunting.io
Opensource Threat Hunting & Intelligence (NCSC-UK) WellMess is malware written in either Golang or .NET and has been in use since at least 2018. WellMess was first reported on by JPCERT and LAC researchers in July 2018. It is named after one of the function names in the malware -'wellmess'. WellMess is a lightweight malware designed to execute arbitrary shell commands, upload and download ...
-
web:www.cisa.gov
The files are variants of the malware family known as "WellMess". These implants allow a remote operator to establish encrypted command and control (C2) sessions and to securely pass and execute scripts on an infected system.
-
web:www.ncsc.gov.uk
This guidance helps private and public sector organisations deal with the effects of malware (which includes ransomware). It provides actions to help organisations prevent a malware infection, and also steps to take if you're already infected. Following this guidance will reduce: the likelihood of becoming infected the spread of malware throughout your organisation the impact of the infection
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.