TF-MAL-elf.revil
📛 Threat Title
Malware family: REvil
Description
ThreatFox malware family `elf.revil`. Printable name: REvil. Aliases: REvix.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.revil
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/elf.revil
IOC database
- Type
- domain
- Value
elf.revil- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.revil
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/elf.revil
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:any.run
REvil won't run malicious activity on systems where UI and keyboard languages are set to a specific value, such as Russian, Ukrainian, and 18 others. Although Sodinokibi is a "qualitative" type of malware , its execution, and system infection process, in general, is quite straightforward and similar to other ransomware - it decrypts files ...
-
web:arista.my.site.com
Especially when dealing with ransomware, speed of remediation is of the essence and the automated triage, investigation and response that Ava brings to this process helps mitigate impact. FIGURE 13: NDR SITUATION FOR REVIL RANSOMWARE DETECTION Remediation
-
web:blog.qualys.com
Explore the REvil ransomware attack and learn how the REvil group operates. Get detailed insights into REvil attack methods, impact, and mitigation strategies.
-
web:en.wikipedia.org
REvil (Ransomware Evil; also known as Sodinokibi) was a Russia-based [1] or Russian-speaking [2] private ransomware -as-a-service (RaaS) operation. [3] After an attack, REvil would threaten to publish the information on their page Happy Blog unless the ransom was received.
-
web:malpedia.caad.fkie.fraunhofer.de
REvil Beta MD5: bed6fc04aeb785815744706239a1f243 SHA1: 3d0649b5f76dbbff9f86b926afbd18ae028946bf SHA256: 3641b09bf6eae22579d4fd5aae420476a134f5948966944189a70afd8032cb45 * Privilege escalation via CVE-2018-8453 (64-bit only) * Rerun with RunAs to elevate privileges * Implements a requirement that if "exp" is set, privilege escalation must be ...
-
web:medium.com
REvil (Also known as Sodinokibi) was a notourious ransomeware gang based in Russian-speaking countries.The group's signifigant contributions was promoting and adopting the infamous double ...
-
web:thehackernews.com
BKA identified REvil leaders tied to 130 German attacks causing €35.4M damage, exposing key ransomware figures.
-
web:unit42.paloaltonetworks.com
Ransomware cases worked by Unit 42 consultants in the first six months of 2021 reveal insights into the preferred tactics of REvil threat actors.
-
web:www.mitre.org
Abstract This paper goes into detail about the REvil ransomware variant and its operators to provide an in-depth look at how it begins its infection chain and why. The paper also covers publicly available information on REvil's cyber-attacks that targeted industries in the healthcare sector, and why it matters. The paper consists of two main parts. Sections 2 and 3 document the REvil malware ...
-
web:www.sentinelone.com
Learn why REvil ransomware is infamous for massive attacks and data leaks. Explore how it infiltrates networks, demands payments, and cripples operations.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.