s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.snowlight

📛 Threat Title

Malware family: SNOWLIGHT

Category: SNOWLIGHT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.snowlight`. Printable name: SNOWLIGHT.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.snowlight VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.snowlight

IOC database

Type
domain
Value
elf.snowlight
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.snowlight

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.snowlight

References (1)

Remediations (10)

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as SNOWLIGHT .

  • web:cloud.google.com

    After backdoor accounts were configured, they attempted to self-patch the vulnerability using an F5-provided mitigation script " mitigation .sh ". Mandiant assesses that this was an attempt to limit subsequent exploitation of the system by additional unrelated threat actors attempting to access the appliance.

  • web:gbhackers.com

    Microsoft Defender Vulnerability Management (MDVM) helps surface vulnerable package inventory and track remediation progress across organizational infrastructure. Microsoft Defender for Cloud customers can use security explorer templates to locate exposed containers running vulnerable container images and vulnerable virtual machines.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to sysdig, SNOWLIGHT is used as a dropper for its fileless payload (vshell).

  • web:rhisac.org

    Mitigations Mandiant provided the following remediation recommendations: Restrict access to the F5 TMUI from the internet. Immediately apply the F5 mitigation script published in K000137353 to any vulnerable F5 appliances. Investigate vulnerable F5 appliances for evidence of compromise. In the event of an F5 compromise:

  • web:socprime.com

    UNC6692 used Teams phishing, AutoHotKey, and SNOW malware with rogue extensions and cloud services to steal data and move laterally.

  • web:www.broadcom.com

    Recent malicious campaigns attributed to the UNC5174 threat group have been reported to exploit F5 BIG-IP (CVE-2023-46747) and Connectwise ScreenConnect (CVE-2024-1709) vulnerabilities for malware delivery. One malware variant, SnowLight , is a C-based downloader for Linux, used by the threat actors to download and execute secondary payloads on the infected machines. GoreVerse, GoHeavy and ...

  • web:www.hivepro.com

    Malware : SNOWLIGHT , GOHEAVY, GOREVERSE, and SUPERSHELL Attack: UNC5174, a threat actor believed to be associated with China, has been identified exploiting various vulnerabilities and deploying custom tools such as SNOWLIGHT , GOHEAVY, and GOREVERSE for post-exploitation activities.

  • web:www.sysdig.com

    The downloaded executable, dnsloger, is detected on VT as part of the SNOWLIGHT malware family used by UNC5174, as previously reported by HivePro. The malware performs several actions that show a more in-depth knowledge of Linux internals, persistence, defense evasion, and injection techniques.

  • web:www.theregister.com

    In this attack, upon gaining access to victims' machines, the malicious bash script downloads and executes two payloads: dnsloger, which is part of the SNOWLIGHT malware family , and system_worker, which drops a Sliver implant and VShell.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.