TF-MAL-elf.dreambus
📛 Threat Title
Malware family: DreamBus
Description
ThreatFox malware family `elf.dreambus`. Printable name: DreamBus.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.dreambus
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.dreambus
IOC database
- Type
- domain
- Value
elf.dreambus- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.dreambus
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.dreambus
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.netmanageit.com
Description Zscaler's ThreatLabz research team has been tracking the Linux-based malware family known as DreamBus . Not much has changed in the last few years other than minor bug fixes, and slight modifications to evade detection from security software. However, in the last 6 months, the threat actor operating DreamBus has introduced two new modules to target vulnerabilities in Metabase and ...
-
web:blogs.juniper.net
To protect organizations from DreamBus malware , RocketMQ and similar attacks, Juniper highly recommends implementing robust patch management processes to ensure any would-be vulnerable systems are updated in a timely manner and protected against these and an evolving set of malicious threats.
-
web:knowledge.broadcom.com
According to recent reports, modular botnet known as DreamBus has resurfaced in a newly observed campaign that leverages this RocketMQ vulnerability for initial access and malware distribution. DreamBus capabilities includes bash script execution as well as download and execution of additional modules and XMRig coinminer payloads.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the DreamBus malware family including references, samples and yara signatures.
-
web:malware.news
Introduction Zscaler's ThreatLabz research team has been tracking the Linux-based malware family known as DreamBus . Not much has changed in the last few years other than minor bug fixes, and slight modifications to evade detection from security software. However, in the last 6 months, the threat actor operating DreamBus has introduced two new modules to target vulnerabilities in Metabase and ...
-
web:www.bleepingcomputer.com
The latest news about DreamBus DreamBus malware exploits RocketMQ flaw to infect servers A new version of the DreamBus botnet malware exploits a critical-severity remote code execution ...
-
web:www.hivepro.com
A critical vulnerability (CVE-2023-33246) in RocketMQ servers was exposed in May 2023, allowing for remote code execution. Exploitation of this vulnerability was observed since June 2023. This led to a series of attacks where threat actors infiltrated systems and installed the DreamBus malware . The attacks started in early June, peaked in mid-June, and targeted multiple ports in addition to ...
-
web:www.rescana.com
The DreamBus botnet, a notorious Linux-based botnet, has been observed exploiting this vulnerability to gain initial access and deploy malicious payloads. This report provides a comprehensive analysis of the exploitation of CVE-2023-33246, detailing the methods used by threat actors, the payloads involved, and the mitigation strategies to ...
-
web:www.securityweek.com
The DreamBus botnet has resurfaced and it has been exploiting a recently patched Apache RocketMQ vulnerability to deliver a Monero miner.
-
web:www.zscaler.com
Introduction Zscaler's ThreatLabz research team has been tracking the Linux-based malware family known as DreamBus . Not much has changed in the last few years other than minor bug fixes, and slight modifications to evade detection from security software. However, in the last 6 months, the threat actor operating DreamBus has introduced two new modules to target vulnerabilities in Metabase and ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.