TF-MAL-elf.systembc
📛 Threat Title
Malware family: SystemBC
Description
ThreatFox malware family `elf.systembc`. Printable name: SystemBC.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.systembc
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.systembc
IOC database
- Type
- domain
- Value
elf.systembc- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.systembc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.systembc
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybersecuritynews.com
The SystemBC malware family , a persistent threat first documented in 2019, has evolved into a massive botnet infrastructure controlling over 10,000 hijacked devices globally. Functioning primarily as a SOCKS5 proxy and a backdoor, this malware enables threat actors to mask their malicious traffic and maintain long-term access to compromised networks. By converting infected systems into relays ...
-
web:intel.mjolnirsecurity.com
SystemBC is a C-language proxy backdoor first observed in June 2019, originally sold as an underground networking tool. It has since evolved into a critical enabler for ransomware operations, providing encrypted SOCKS5 proxy tunneling and TOR-based command-and-control to groups including Ryuk, Conti, DarkSide (Colonial Pipeline), and Black Basta. SystemBC was initially marketed on Russian ...
-
web:malpedia.caad.fkie.fraunhofer.de
SystemBC is a multiplatform proxy malware active since August 2019. It creates SOCKS5 network tunnels in the victim's network and connects to its C2 server using a custom, RC4-encrypted protocol. It can also download and execute additional malware , with payloads either written to disk or mapped into memory. The SystemBC kit, including the C2 panel, server, and malware executables, is sold in ...
-
web:research.checkpoint.com
SystemBC Infections During an incident response case, an affiliate of The Gentlemen Ransomware‑as‑a‑Service (RaaS) deployed SystemBC , a proxy malware , on the compromised host. SystemBC establishes SOCKS5 network tunnels within the victim's environment and connects to its C&C server using a custom RC4‑encrypted protocol.
-
web:thehackernews.com
SystemBC Malware's C2 Server Analysis Exposes Payload Delivery Tricks Ravie Lakshmanan Jan 25, 2024 Remote Access Trojan Cybersecurity researchers have shed light on the command-and-control (C2) server workings of a known malware family called SystemBC .
-
web:www.bleepingcomputer.com
A SystemBC proxy malware botnet of more than 1,570 hosts, believed to be corporate victims, has been discovered following an investigation into a Gentlemen ransomware attack carried out by a gang ...
-
web:www.de-line.net
This article provides an in-depth analysis of the SystemBC botnet's infection vectors, core functionalities, and defense strategies. It highlights how SystemBC infects devices via Exchange ProxyShell vulnerabilities and phishing emails to build a large proxy network. The article also recommends multi-layered defenses including patching, traffic monitoring, malicious file scanning, and access ...
-
web:www.kroll.com
Throughout Q2 and Q3 2023, Kroll has observed an increased use of the malicious " SYSTEMBC " tool to maintain access in a compromised network. Our experts conducted research into the SYSTEMBC command and control (C2) server. Learn more.
-
web:www.securityweek.com
Malware & Threats SystemBC Infects 10,000 Devices After Defying Law Enforcement Takedown The malware is known for dropping ransomware and other payloads, and for abusing infected machines to proxy traffic.
-
web:www.shadowserver.org
The data in this SystemBC Historical Bot Infections Special Report was provided to Shadowserver by the Operation Endgame Law Enforcement partners to disseminate to National CERTs/CSIRTs and network owners globally, to maximize remediation efforts.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.