TF-MAL-elf.xbash
📛 Threat Title
Malware family: Xbash
Description
ThreatFox malware family `elf.xbash`. Printable name: Xbash.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.xbash
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.xbash
IOC database
- Type
- domain
- Value
elf.xbash- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.xbash
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.xbash
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
Xbash is a malware family that has targeted Linux and Microsoft Windows servers. The malware has been tied to the Iron Group, a threat actor group known for previous ransomware attacks.
-
web:github.com
Unit 42 researchers have found a new malware family that is targeting Linux and Microsoft Windows servers. We can tie this malware , which we have named Xbash , to the Iron Group, a threat actor group known for previous ransomware attacks.> Xbash has ransomware and coinmining capabilities. It also has self-propagating capabilities (meaning it has worm-like characteristics similar to WannaCry or ...
-
web:imtr.net
- YARA rules: [Not specified in the article] ## Mitigation Strategies - **Database Hardening:** Addressing specific weaknesses like weak passwords, misconfigurations, and disabled security features on targeted database systems. - **Network Segmentation:** Limiting network exposure of database servers.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Xbash malware family including references, samples and yara signatures.
-
web:optocrypto.com
The publication says it is a new malware family associated with the Iron Group of hackers known for their past ransomware attacks. However, Xbash has shown a much more complex attack vector, combining the exploitation of multiple vulnerabilities and weak passwords.
-
web:solutionsreview.com
Threat actor group Rocke, apparently associated with the Iron cybercrime group, developed Xbash and this latest malware . Unit 42's report on the new malware revealed that it was capable of removing cloud security products from the user's computer. Specifically, it can deactivate programs released by Tencent Cloud and Alibaba Cloud.
-
web:unit42.paloaltonetworks.com
Executive Summary: Unit 42 researchers have found a new malware family that is targeting Linux and Microsoft Windows servers that we have named XBash . We can tie this malware to the Iron Group, a threat actor group known for ransomware attacks in the past. Xbash has ransomware and coinmining capabilities. It also has self-propagating capabilities (meaning it has worm-like characteristics ...
-
web:www.iobit.com
Days ago, a newly discovered malware named Xbash was reported to have combined ransomware, coinminer, botnet and worm feature together, according to the research from Palo Alto Networks. Xbash is named based on the name of the malicious code's original main module. The malware attacks both Windows and Linux systems in different ways. It deletes database on Linux while mines for crypto ...
-
web:www.levelblue.com
However, the focus will be on the database attack component of the Xbash malware . Xbash Overview Xbash is a multifaceted malware with capabilities ranging from database ransomware, botnet capabilities, cryptomining, and self-propagation. By leveraging its botnet traits, Xbash can recruit infected systems to execute further attacks.
-
web:www.securityweek.com
A newly discovered piece of Linux malware that features both ransomware and crypto-currency mining capabilities appears designed to target enterprise intranets, Palo Alto Networks security researchers say. Dubbed Xbash and believed to be tied to the Iron Group, a threat actor known for previous ransomware attacks, the malware can target both Linux and Windows servers. It contains a Python ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.