s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.notrobin

📛 Threat Title

Malware family: NOTROBIN

Category: NOTROBIN First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.notrobin`. Printable name: NOTROBIN. Aliases: remove_bds.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.notrobin VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.notrobin

IOC database

Type
domain
Value
elf.notrobin
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.notrobin

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.notrobin

References (1)

Remediations (10)

  • web:cloud.google.com

    Within these, something caught our eye: one particular threat actor that's been deploying a previously-unseen payload for which we've created the code family NOTROBIN . Upon gaining access to a vulnerable NetScaler device, this actor cleans up known malware and deploys NOTROBIN to block subsequent exploitation attempts!

  • web:consumer.ftc.gov

    Malware is one of the biggest threats to the security of your computer, tablet, phone, and other devices. Learn how to protect yourself, how to tell if your device has malware , and how to remove it.

  • web:malpedia.caad.fkie.fraunhofer.de

    FireEye states that NOTROBIN is a utility written in Go 1.10 and compiled to a 64-bit ELF binary for BSD systems. It periodically scans for and deletes files matching filename patterns and content characteristics. The purpose seems to be to block exploitation attempts against the CVE-2019-19781 vulnerability; however, FireEye believes that NOTROBIN provides backdoor access to the compromised ...

  • web:securityaffairs.com

    "One particular threat actor that's been deploying a previously-unseen payload for which we've created the code family NOTROBIN ." reads a report published by FireEye. "Upon gaining access to a vulnerable NetScaler device, this actor cleans up known malware and deploys NOTROBIN to block subsequent exploitation attempts!

  • web:www.bleepingcomputer.com

    An unknown threat actor is currently scanning for and securing vulnerable Citrix ADC servers against CVE-2019-19781 exploitation attempts, while also backdooring them for future access.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.darkreading.com

    FireEye has found evidence of an actor first breaching unmitigated Citrix ADC servers, installing a mitigation patch for CVE-2019-19781 and then deploying a new malware payload they call NOTROBIN .

  • web:www.ic3.gov

    Overview Threat actors are deploying ATM jackpotting malware , including the Ploutus family malware , to infect ATMs and force them to dispense cash. Ploutus malware exploits the eXtensions for Financial Services (XFS), the layer of software that instructs an ATM what to physically do. When a legitimate transaction occurs, the ATM application sends instructions through XFS for bank authorization ...

  • web:www.ncsc.gov.uk

    This guidance helps private and public sector organisations deal with the effects of malware (which includes ransomware). It provides actions to help organisations prevent a malware infection, and also steps to take if you're already infected. Following this guidance will reduce: the likelihood of becoming infected the spread of malware throughout your organisation the impact of the infection

  • web:www.securityweek.com

    One of the attacks that stands out from the crowd, FireEye says, is cleaning up known malware from the vulnerable deployments and deploys a previously-unseen payload known as NOTROBIN . The malware blocks subsequent exploitation attempts, but also maintains backdoor access, likely in preparation for a future campaign.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.