s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.systembc

📛 Threat Title

Malware family: SystemBC

Category: SystemBC First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.systembc`. Printable name: SystemBC.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.systembc VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.systembc

IOC database

Type
domain
Value
elf.systembc
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.systembc

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.systembc

References (1)

Remediations (10)

  • web:cybersecuritynews.com

    The SystemBC malware family , a persistent threat first documented in 2019, has evolved into a massive botnet infrastructure controlling over 10,000 hijacked devices globally. Functioning primarily as a SOCKS5 proxy and a backdoor, this malware enables threat actors to mask their malicious traffic and maintain long-term access to compromised networks. By converting infected systems into relays ...

  • web:intel.mjolnirsecurity.com

    SystemBC is a C-language proxy backdoor first observed in June 2019, originally sold as an underground networking tool. It has since evolved into a critical enabler for ransomware operations, providing encrypted SOCKS5 proxy tunneling and TOR-based command-and-control to groups including Ryuk, Conti, DarkSide (Colonial Pipeline), and Black Basta. SystemBC was initially marketed on Russian ...

  • web:malpedia.caad.fkie.fraunhofer.de

    SystemBC is a multiplatform proxy malware active since August 2019. It creates SOCKS5 network tunnels in the victim's network and connects to its C2 server using a custom, RC4-encrypted protocol. It can also download and execute additional malware , with payloads either written to disk or mapped into memory. The SystemBC kit, including the C2 panel, server, and malware executables, is sold in ...

  • web:research.checkpoint.com

    SystemBC Infections During an incident response case, an affiliate of The Gentlemen Ransomware‑as‑a‑Service (RaaS) deployed SystemBC , a proxy malware , on the compromised host. SystemBC establishes SOCKS5 network tunnels within the victim's environment and connects to its C&C server using a custom RC4‑encrypted protocol.

  • web:thehackernews.com

    SystemBC Malware's C2 Server Analysis Exposes Payload Delivery Tricks Ravie Lakshmanan Jan 25, 2024 Remote Access Trojan Cybersecurity researchers have shed light on the command-and-control (C2) server workings of a known malware family called SystemBC .

  • web:www.bleepingcomputer.com

    A SystemBC proxy malware botnet of more than 1,570 hosts, believed to be corporate victims, has been discovered following an investigation into a Gentlemen ransomware attack carried out by a gang ...

  • web:www.de-line.net

    This article provides an in-depth analysis of the SystemBC botnet's infection vectors, core functionalities, and defense strategies. It highlights how SystemBC infects devices via Exchange ProxyShell vulnerabilities and phishing emails to build a large proxy network. The article also recommends multi-layered defenses including patching, traffic monitoring, malicious file scanning, and access ...

  • web:www.kroll.com

    Throughout Q2 and Q3 2023, Kroll has observed an increased use of the malicious " SYSTEMBC " tool to maintain access in a compromised network. Our experts conducted research into the SYSTEMBC command and control (C2) server. Learn more.

  • web:www.securityweek.com

    Malware & Threats SystemBC Infects 10,000 Devices After Defying Law Enforcement Takedown The malware is known for dropping ransomware and other payloads, and for abusing infected machines to proxy traffic.

  • web:www.shadowserver.org

    The data in this SystemBC Historical Bot Infections Special Report was provided to Shadowserver by the Operation Endgame Law Enforcement partners to disseminate to National CERTs/CSIRTs and network owners globally, to maximize remediation efforts.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.