s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.xbash

📛 Threat Title

Malware family: Xbash

Category: Xbash First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.xbash`. Printable name: Xbash.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.xbash VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.xbash

IOC database

Type
domain
Value
elf.xbash
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.xbash

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.xbash

References (1)

Remediations (10)

  • web:attack.mitre.org

    Xbash is a malware family that has targeted Linux and Microsoft Windows servers. The malware has been tied to the Iron Group, a threat actor group known for previous ransomware attacks.

  • web:github.com

    Unit 42 researchers have found a new malware family that is targeting Linux and Microsoft Windows servers. We can tie this malware , which we have named Xbash , to the Iron Group, a threat actor group known for previous ransomware attacks.> Xbash has ransomware and coinmining capabilities. It also has self-propagating capabilities (meaning it has worm-like characteristics similar to WannaCry or ...

  • web:imtr.net

    - YARA rules: [Not specified in the article] ## Mitigation Strategies - **Database Hardening:** Addressing specific weaknesses like weak passwords, misconfigurations, and disabled security features on targeted database systems. - **Network Segmentation:** Limiting network exposure of database servers.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Xbash malware family including references, samples and yara signatures.

  • web:optocrypto.com

    The publication says it is a new malware family associated with the Iron Group of hackers known for their past ransomware attacks. However, Xbash has shown a much more complex attack vector, combining the exploitation of multiple vulnerabilities and weak passwords.

  • web:solutionsreview.com

    Threat actor group Rocke, apparently associated with the Iron cybercrime group, developed Xbash and this latest malware . Unit 42's report on the new malware revealed that it was capable of removing cloud security products from the user's computer. Specifically, it can deactivate programs released by Tencent Cloud and Alibaba Cloud.

  • web:unit42.paloaltonetworks.com

    Executive Summary: Unit 42 researchers have found a new malware family that is targeting Linux and Microsoft Windows servers that we have named XBash . We can tie this malware to the Iron Group, a threat actor group known for ransomware attacks in the past. Xbash has ransomware and coinmining capabilities. It also has self-propagating capabilities (meaning it has worm-like characteristics ...

  • web:www.iobit.com

    Days ago, a newly discovered malware named Xbash was reported to have combined ransomware, coinminer, botnet and worm feature together, according to the research from Palo Alto Networks. Xbash is named based on the name of the malicious code's original main module. The malware attacks both Windows and Linux systems in different ways. It deletes database on Linux while mines for crypto ...

  • web:www.levelblue.com

    However, the focus will be on the database attack component of the Xbash malware . Xbash Overview Xbash is a multifaceted malware with capabilities ranging from database ransomware, botnet capabilities, cryptomining, and self-propagation. By leveraging its botnet traits, Xbash can recruit infected systems to execute further attacks.

  • web:www.securityweek.com

    A newly discovered piece of Linux malware that features both ransomware and crypto-currency mining capabilities appears designed to target enterprise intranets, Palo Alto Networks security researchers say. Dubbed Xbash and believed to be tied to the Iron Group, a threat actor known for previous ransomware attacks, the malware can target both Linux and Windows servers. It contains a Python ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.