TF-MAL-elf.corona
📛 Threat Title
Malware family: elf.corona
Description
ThreatFox malware family `elf.corona`.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.corona
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.corona
IOC database
- Type
- domain
- Value
elf.corona- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.corona
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.corona
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybersecuritynews.com
Linux malware targeting cloud systems is surging, with ELF binaries adapted for cloud use and APT attacks up 45% amid a 388% alert spike.
-
web:gbhackers.com
As cloud migration accelerates, threat actors are shifting their focus to Linux ELF malware , tailoring proven techniques for cloud environments. The rise of backdoors, wipers, and sophisticated evasion methods such as dynamic linker hijacking and rootkit functionality means defenders must stay ahead with advanced detection and response.
-
web:github.com
The goal of this project would be to expand upon previous work for Windows executables (PE files) and see if similar ideas and methods would apply for Linux executables (ELF files). Ultimately, these new malware samples would then be used to train new malware detectors to perform better against obfuscated malware in the future.
-
web:homepages.uc.edu
Hamilton College, NY Abstract—This paper investigates evasion attacks on end-to-end deep-learning malware detection over ELF (Executable and Linkable Format) binaries. We show that an attacker can deliberately modify bytes in a malware ELF binary such that a well-trained neural network is misled and predicts it as benign. We examine five methods that can modify ELF binaries without affecting ...
-
web:ieeexplore.ieee.org
This paper investigates evasion attacks on end-to-end deep-learning malware detection over ELF (Executable and Linkable Format) binaries. We show that an attacker can deliberately modify bytes in a malware ELF binary such that a well-trained neural network is misled and predicts it as benign. We examine five methods that can modify ELF binaries without affecting functionalities and leverage ...
-
web:mabonmn.github.io
We examine five methods that can modify ELF binaries without affecting functionalities and leverage them in evasion attacks. We explore two state-of-the-art end-to-end deep learning malware detectors, including MalConv and FireEyeNet, over a real-world dataset with 1,422 ELF binaries.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the malware family including references, samples and yara signatures.
-
web:unit42.paloaltonetworks.com
The ELF malware samples threat actors use will include backdoors, droppers, remote access Trojans (RATs), data wipers and vulnerability-exploiting binaries. During our investigation, we focused on five ELF-based malware families, each of which threat actor groups have used to target cloud environments during their operations.
-
web:www.cyfirma.com
EXECUTIVE SUMMARY CYFIRMA has uncovered an active cyber-espionage campaign conducted by APT36 (Transparent Tribe), a Pakistan-based threat actor known for persistent targeting of Indian government and strategic sectors. The latest activity demonstrates the group's growing technical maturity and adaptability, as it deploys tailored malware specifically crafted to compromise Linux-based BOSS ...
-
web:www.sonicwall.com
Overview This week, the SonicWall Capture Labs Threat Research team analyzed a sample of a malicious ELF file infector that shares characteristics of IoT botnet malware . The sample demonstrates self-propagation capabilities, file system scanning, and selective infection mechanisms targeting other ELF binaries. Infection Cycle
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.