TF-MAL-elf.unidentified_004
📛 Threat Title
Malware family: Unidentified ELF 004
Description
ThreatFox malware family `elf.unidentified_004`. Printable name: Unidentified ELF 004.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:anish833.github.io
The ELF format gives Linux its powerful and flexible execution model — but that same power can be turned against it. Malware authors exploit ELF internals to hide code, hijack entry points, and persist stealthily, often bypassing conventional detection.
-
web:attack.mitre.org
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls ...
-
web:bazaar.abuse.ch
Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with elf .
-
web:cylab.be
ELF header manipulation can significantly impact how analysis tools interpret binaries and whether an executable runs correctly. While some modifications, like changing the OSABI or padding bytes, may go unnoticed, others, such as corrupting the ELF magic or e_type, render the file unreadable or unexecutable.
-
web:docs.sophos.com
Malicious behavior types Aug 19, 2024 This page explains the names we use for malicious behavior detected on computers or servers.
-
web:github.com
This repository contains relevant samples and data related to the ELF Malware Analysis 101 articles - intezer/ ELF - Malware -Analysis-101
-
web:ieee-dataport.org
The overall sample spans from 2020 to July 2024 and is primarily sourced from VirusShare and Bazaar-daily. Both sources are publicly available. The dataset has been filtered to include only ELF files (both statically and dynamically linked). The naming convention for all ELF files in our dataset is ` {SHA256}.elf`, including both benign and malicious samples. There are four main parts in the ...
-
web:malpedia.caad.fkie.fraunhofer.de
Unidentified ELF 004 Propose Change Actor (s): APT31 Implant used by APT31 on compromised SOHO infrastructure, tries to camouflage as a tool ("unifi-video") related to Ubiquiti UniFi surveillance cameras.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.sonicwall.com
Overview This week, the SonicWall Capture Labs Threat Research team analyzed a sample of a malicious ELF file infector that shares characteristics of IoT botnet malware . The sample demonstrates self-propagation capabilities, file system scanning, and selective infection mechanisms targeting other ELF binaries. Infection Cycle
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.