s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.wellmess

📛 Threat Title

Malware family: elf.wellmess

Category: elf.wellmess First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.wellmess`.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.wellmess VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.wellmess

IOC database

Type
domain
Value
elf.wellmess
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.wellmess

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.wellmess

References (1)

Remediations (10)

  • web:apt.etda.or.th

    Last change to this tool card: 30 December 2022 Download this tool card in JSON format All groups using tool WellMess

  • web:apt.securelist.com

    WellMess is a Remote Access Trojan that has been deployed against high-profile targets in MENA and the EU, as well as companies conducting COVID-19 vaccine research.

  • web:attack.mitre.org

    WellMess is lightweight malware family with variants written in .NET and Golang that has been in use since at least 2018 by APT29. [1] [2] [3]

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as WellMess.

  • web:iopscience.iop.org

    By understanding these structural differences between malicious and benign ELF files, security analysts can develop more effective detection and mitigation strategies to safeguard systems against evolving malware threats.

  • web:learn.microsoft.com

    Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the elf.wellmess malware family including references, samples and yara signatures.

  • web:openhunting.io

    Opensource Threat Hunting & Intelligence (NCSC-UK) WellMess is malware written in either Golang or .NET and has been in use since at least 2018. WellMess was first reported on by JPCERT and LAC researchers in July 2018. It is named after one of the function names in the malware -'wellmess'. WellMess is a lightweight malware designed to execute arbitrary shell commands, upload and download ...

  • web:www.cisa.gov

    The files are variants of the malware family known as "WellMess". These implants allow a remote operator to establish encrypted command and control (C2) sessions and to securely pass and execute scripts on an infected system.

  • web:www.ncsc.gov.uk

    This guidance helps private and public sector organisations deal with the effects of malware (which includes ransomware). It provides actions to help organisations prevent a malware infection, and also steps to take if you're already infected. Following this guidance will reduce: the likelihood of becoming infected the spread of malware throughout your organisation the impact of the infection

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.