TF-MAL-elf.snowlight
📛 Threat Title
Malware family: SNOWLIGHT
Description
ThreatFox malware family `elf.snowlight`. Printable name: SNOWLIGHT.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.snowlight
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.snowlight
IOC database
- Type
- domain
- Value
elf.snowlight- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.snowlight
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.snowlight
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as SNOWLIGHT .
-
web:cloud.google.com
After backdoor accounts were configured, they attempted to self-patch the vulnerability using an F5-provided mitigation script " mitigation .sh ". Mandiant assesses that this was an attempt to limit subsequent exploitation of the system by additional unrelated threat actors attempting to access the appliance.
-
web:gbhackers.com
Microsoft Defender Vulnerability Management (MDVM) helps surface vulnerable package inventory and track remediation progress across organizational infrastructure. Microsoft Defender for Cloud customers can use security explorer templates to locate exposed containers running vulnerable container images and vulnerable virtual machines.
-
web:malpedia.caad.fkie.fraunhofer.de
According to sysdig, SNOWLIGHT is used as a dropper for its fileless payload (vshell).
-
web:rhisac.org
Mitigations Mandiant provided the following remediation recommendations: Restrict access to the F5 TMUI from the internet. Immediately apply the F5 mitigation script published in K000137353 to any vulnerable F5 appliances. Investigate vulnerable F5 appliances for evidence of compromise. In the event of an F5 compromise:
-
web:socprime.com
UNC6692 used Teams phishing, AutoHotKey, and SNOW malware with rogue extensions and cloud services to steal data and move laterally.
-
web:www.broadcom.com
Recent malicious campaigns attributed to the UNC5174 threat group have been reported to exploit F5 BIG-IP (CVE-2023-46747) and Connectwise ScreenConnect (CVE-2024-1709) vulnerabilities for malware delivery. One malware variant, SnowLight , is a C-based downloader for Linux, used by the threat actors to download and execute secondary payloads on the infected machines. GoreVerse, GoHeavy and ...
-
web:www.hivepro.com
Malware : SNOWLIGHT , GOHEAVY, GOREVERSE, and SUPERSHELL Attack: UNC5174, a threat actor believed to be associated with China, has been identified exploiting various vulnerabilities and deploying custom tools such as SNOWLIGHT , GOHEAVY, and GOREVERSE for post-exploitation activities.
-
web:www.sysdig.com
The downloaded executable, dnsloger, is detected on VT as part of the SNOWLIGHT malware family used by UNC5174, as previously reported by HivePro. The malware performs several actions that show a more in-depth knowledge of Linux internals, persistence, defense evasion, and injection techniques.
-
web:www.theregister.com
In this attack, upon gaining access to victims' machines, the malicious bash script downloads and executes two payloads: dnsloger, which is part of the SNOWLIGHT malware family , and system_worker, which drops a Sliver implant and VShell.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.