s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.dreambus

📛 Threat Title

Malware family: DreamBus

Category: DreamBus First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.dreambus`. Printable name: DreamBus.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.dreambus VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.dreambus

IOC database

Type
domain
Value
elf.dreambus
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.dreambus

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.dreambus

References (1)

Remediations (10)

  • web:blog.netmanageit.com

    Description Zscaler's ThreatLabz research team has been tracking the Linux-based malware family known as DreamBus . Not much has changed in the last few years other than minor bug fixes, and slight modifications to evade detection from security software. However, in the last 6 months, the threat actor operating DreamBus has introduced two new modules to target vulnerabilities in Metabase and ...

  • web:blogs.juniper.net

    To protect organizations from DreamBus malware , RocketMQ and similar attacks, Juniper highly recommends implementing robust patch management processes to ensure any would-be vulnerable systems are updated in a timely manner and protected against these and an evolving set of malicious threats.

  • web:knowledge.broadcom.com

    According to recent reports, modular botnet known as DreamBus has resurfaced in a newly observed campaign that leverages this RocketMQ vulnerability for initial access and malware distribution. DreamBus capabilities includes bash script execution as well as download and execution of additional modules and XMRig coinminer payloads.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the DreamBus malware family including references, samples and yara signatures.

  • web:malware.news

    Introduction Zscaler's ThreatLabz research team has been tracking the Linux-based malware family known as DreamBus . Not much has changed in the last few years other than minor bug fixes, and slight modifications to evade detection from security software. However, in the last 6 months, the threat actor operating DreamBus has introduced two new modules to target vulnerabilities in Metabase and ...

  • web:www.bleepingcomputer.com

    The latest news about DreamBus DreamBus malware exploits RocketMQ flaw to infect servers A new version of the DreamBus botnet malware exploits a critical-severity remote code execution ...

  • web:www.hivepro.com

    A critical vulnerability (CVE-2023-33246) in RocketMQ servers was exposed in May 2023, allowing for remote code execution. Exploitation of this vulnerability was observed since June 2023. This led to a series of attacks where threat actors infiltrated systems and installed the DreamBus malware . The attacks started in early June, peaked in mid-June, and targeted multiple ports in addition to ...

  • web:www.rescana.com

    The DreamBus botnet, a notorious Linux-based botnet, has been observed exploiting this vulnerability to gain initial access and deploy malicious payloads. This report provides a comprehensive analysis of the exploitation of CVE-2023-33246, detailing the methods used by threat actors, the payloads involved, and the mitigation strategies to ...

  • web:www.securityweek.com

    The DreamBus botnet has resurfaced and it has been exploiting a recently patched Apache RocketMQ vulnerability to deliver a Monero miner.

  • web:www.zscaler.com

    Introduction Zscaler's ThreatLabz research team has been tracking the Linux-based malware family known as DreamBus . Not much has changed in the last few years other than minor bug fixes, and slight modifications to evade detection from security software. However, in the last 6 months, the threat actor operating DreamBus has introduced two new modules to target vulnerabilities in Metabase and ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.