s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.revil

📛 Threat Title

Malware family: REvil

Category: REvil First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.revil`. Printable name: REvil. Aliases: REvix.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.revil VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/elf.revil

IOC database

Type
domain
Value
elf.revil
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.revil

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/elf.revil

References (1)

Remediations (10)

  • web:any.run

    REvil won't run malicious activity on systems where UI and keyboard languages are set to a specific value, such as Russian, Ukrainian, and 18 others. Although Sodinokibi is a "qualitative" type of malware , its execution, and system infection process, in general, is quite straightforward and similar to other ransomware - it decrypts files ...

  • web:arista.my.site.com

    Especially when dealing with ransomware, speed of remediation is of the essence and the automated triage, investigation and response that Ava brings to this process helps mitigate impact. FIGURE 13: NDR SITUATION FOR REVIL RANSOMWARE DETECTION Remediation

  • web:blog.qualys.com

    Explore the REvil ransomware attack and learn how the REvil group operates. Get detailed insights into REvil attack methods, impact, and mitigation strategies.

  • web:en.wikipedia.org

    REvil (Ransomware Evil; also known as Sodinokibi) was a Russia-based [1] or Russian-speaking [2] private ransomware -as-a-service (RaaS) operation. [3] After an attack, REvil would threaten to publish the information on their page Happy Blog unless the ransom was received.

  • web:malpedia.caad.fkie.fraunhofer.de

    REvil Beta MD5: bed6fc04aeb785815744706239a1f243 SHA1: 3d0649b5f76dbbff9f86b926afbd18ae028946bf SHA256: 3641b09bf6eae22579d4fd5aae420476a134f5948966944189a70afd8032cb45 * Privilege escalation via CVE-2018-8453 (64-bit only) * Rerun with RunAs to elevate privileges * Implements a requirement that if "exp" is set, privilege escalation must be ...

  • web:medium.com

    REvil (Also known as Sodinokibi) was a notourious ransomeware gang based in Russian-speaking countries.The group's signifigant contributions was promoting and adopting the infamous double ...

  • web:thehackernews.com

    BKA identified REvil leaders tied to 130 German attacks causing €35.4M damage, exposing key ransomware figures.

  • web:unit42.paloaltonetworks.com

    Ransomware cases worked by Unit 42 consultants in the first six months of 2021 reveal insights into the preferred tactics of REvil threat actors.

  • web:www.mitre.org

    Abstract This paper goes into detail about the REvil ransomware variant and its operators to provide an in-depth look at how it begins its infection chain and why. The paper also covers publicly available information on REvil's cyber-attacks that targeted industries in the healthcare sector, and why it matters. The paper consists of two main parts. Sections 2 and 3 document the REvil malware ...

  • web:www.sentinelone.com

    Learn why REvil ransomware is infamous for massive attacks and data leaks. Explore how it infiltrates networks, demands payments, and cripples operations.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.