TF-MAL-elf.notrobin
📛 Threat Title
Malware family: NOTROBIN
Description
ThreatFox malware family `elf.notrobin`. Printable name: NOTROBIN. Aliases: remove_bds.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.notrobin
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.notrobin
IOC database
- Type
- domain
- Value
elf.notrobin- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.notrobin
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.notrobin
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cloud.google.com
Within these, something caught our eye: one particular threat actor that's been deploying a previously-unseen payload for which we've created the code family NOTROBIN . Upon gaining access to a vulnerable NetScaler device, this actor cleans up known malware and deploys NOTROBIN to block subsequent exploitation attempts!
-
web:consumer.ftc.gov
Malware is one of the biggest threats to the security of your computer, tablet, phone, and other devices. Learn how to protect yourself, how to tell if your device has malware , and how to remove it.
-
web:malpedia.caad.fkie.fraunhofer.de
FireEye states that NOTROBIN is a utility written in Go 1.10 and compiled to a 64-bit ELF binary for BSD systems. It periodically scans for and deletes files matching filename patterns and content characteristics. The purpose seems to be to block exploitation attempts against the CVE-2019-19781 vulnerability; however, FireEye believes that NOTROBIN provides backdoor access to the compromised ...
-
web:securityaffairs.com
"One particular threat actor that's been deploying a previously-unseen payload for which we've created the code family NOTROBIN ." reads a report published by FireEye. "Upon gaining access to a vulnerable NetScaler device, this actor cleans up known malware and deploys NOTROBIN to block subsequent exploitation attempts!
-
web:www.bleepingcomputer.com
An unknown threat actor is currently scanning for and securing vulnerable Citrix ADC servers against CVE-2019-19781 exploitation attempts, while also backdooring them for future access.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.darkreading.com
FireEye has found evidence of an actor first breaching unmitigated Citrix ADC servers, installing a mitigation patch for CVE-2019-19781 and then deploying a new malware payload they call NOTROBIN .
-
web:www.ic3.gov
Overview Threat actors are deploying ATM jackpotting malware , including the Ploutus family malware , to infect ATMs and force them to dispense cash. Ploutus malware exploits the eXtensions for Financial Services (XFS), the layer of software that instructs an ATM what to physically do. When a legitimate transaction occurs, the ATM application sends instructions through XFS for bank authorization ...
-
web:www.ncsc.gov.uk
This guidance helps private and public sector organisations deal with the effects of malware (which includes ransomware). It provides actions to help organisations prevent a malware infection, and also steps to take if you're already infected. Following this guidance will reduce: the likelihood of becoming infected the spread of malware throughout your organisation the impact of the infection
-
web:www.securityweek.com
One of the attacks that stands out from the crowd, FireEye says, is cleaning up known malware from the vulnerable deployments and deploys a previously-unseen payload known as NOTROBIN . The malware blocks subsequent exploitation attempts, but also maintains backdoor access, likely in preparation for a future campaign.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.