s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.corona

📛 Threat Title

Malware family: elf.corona

Category: elf.corona First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.corona`.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.corona VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.corona

IOC database

Type
domain
Value
elf.corona
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.corona

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.corona

References (1)

Remediations (10)

  • web:cybersecuritynews.com

    Linux malware targeting cloud systems is surging, with ELF binaries adapted for cloud use and APT attacks up 45% amid a 388% alert spike.

  • web:gbhackers.com

    As cloud migration accelerates, threat actors are shifting their focus to Linux ELF malware , tailoring proven techniques for cloud environments. The rise of backdoors, wipers, and sophisticated evasion methods such as dynamic linker hijacking and rootkit functionality means defenders must stay ahead with advanced detection and response.

  • web:github.com

    The goal of this project would be to expand upon previous work for Windows executables (PE files) and see if similar ideas and methods would apply for Linux executables (ELF files). Ultimately, these new malware samples would then be used to train new malware detectors to perform better against obfuscated malware in the future.

  • web:homepages.uc.edu

    Hamilton College, NY Abstract—This paper investigates evasion attacks on end-to-end deep-learning malware detection over ELF (Executable and Linkable Format) binaries. We show that an attacker can deliberately modify bytes in a malware ELF binary such that a well-trained neural network is misled and predicts it as benign. We examine five methods that can modify ELF binaries without affecting ...

  • web:ieeexplore.ieee.org

    This paper investigates evasion attacks on end-to-end deep-learning malware detection over ELF (Executable and Linkable Format) binaries. We show that an attacker can deliberately modify bytes in a malware ELF binary such that a well-trained neural network is misled and predicts it as benign. We examine five methods that can modify ELF binaries without affecting functionalities and leverage ...

  • web:mabonmn.github.io

    We examine five methods that can modify ELF binaries without affecting functionalities and leverage them in evasion attacks. We explore two state-of-the-art end-to-end deep learning malware detectors, including MalConv and FireEyeNet, over a real-world dataset with 1,422 ELF binaries.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the malware family including references, samples and yara signatures.

  • web:unit42.paloaltonetworks.com

    The ELF malware samples threat actors use will include backdoors, droppers, remote access Trojans (RATs), data wipers and vulnerability-exploiting binaries. During our investigation, we focused on five ELF-based malware families, each of which threat actor groups have used to target cloud environments during their operations.

  • web:www.cyfirma.com

    EXECUTIVE SUMMARY CYFIRMA has uncovered an active cyber-espionage campaign conducted by APT36 (Transparent Tribe), a Pakistan-based threat actor known for persistent targeting of Indian government and strategic sectors. The latest activity demonstrates the group's growing technical maturity and adaptability, as it deploys tailored malware specifically crafted to compromise Linux-based BOSS ...

  • web:www.sonicwall.com

    Overview This week, the SonicWall Capture Labs Threat Research team analyzed a sample of a malicious ELF file infector that shares characteristics of IoT botnet malware . The sample demonstrates self-propagation capabilities, file system scanning, and selective infection mechanisms targeting other ELF binaries. Infection Cycle

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.