s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.ransomexx

📛 Threat Title

Malware family: RansomEXX

Category: RansomEXX First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.ransomexx`. Printable name: RansomEXX. Aliases: Defray777.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.ransomexx VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.ransomexx

IOC database

Type
domain
Value
elf.ransomexx
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.ransomexx

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.ransomexx

References (1)

Remediations (10)

  • web:kcm.trellix.com

    Our Threat Research team will continue to monitor and update the RansomEXX ransomware profile and disseminate information that is deemed appropriate regarding the RansomEXX ransomware and victims. How to use this article: If a Threat Hunting table has been created, use the rules contained to search for malware related to this campaign.

  • web:malpedia.caad.fkie.fraunhofer.de

    RansomExx is a ransomware family that targeted multiple companies starting in mid-2020. It shares commonalities with Defray777.

  • web:rasoc.ae

    Introduction: RansomEXX , also known as Defray or Defray777, is a multifaceted ransomware threat that emerged in late 2020. This analysis provides an in-depth exploration of RansomEXX Ransomware, covering its background, target sectors, modus operandi, technical intricacies, detection methods, mitigation strategies, and removal procedures. RansomEXX Ransomware Overview: Emergence: First ...

  • web:us.quickheal.com

    RansomExx is an apt example of how a ransomware family can evolve in finding new ways of infecting machines. The new variant compared to Defray777 shows that the threat actors are improvising with sophisticated modern methods to evade detection by running file-less malware and using advanced intrusion techniques combined with anti-forensic ...

  • web:www.ibm.com

    RansomExx is operated by the DefrayX threat actor group (Hive0091), which is also known for the PyXie malware , Vatet loader, and Defray ransomware strains. The newly discovered ransomware version is named RansomExx2 according to strings found within the ransomware and is designed to run on the Linux operating system.

  • web:www.ransomlook.io

    Description RansomExx is a ransomware family that targeted multiple companies starting in mid-2020. It shares commonalities with Defray777.

  • web:www.ransomware.live

    RansomExx is a ransomware family that targeted multiple companies starting in mid-2020. It shares commonalities with Defray777.

  • web:www.sentinelone.com

    What is RansomEXX Ransomware? RansomEXX (aka Defray, Defray777), a multi-pronged extortion threat, has been observed in the wild since late 2020. RansomEXX is associated with attacks against the Texas Department of Transportation, Groupe Atlantic, and several other large enterprises. There are Windows and Linux variants of this malware family , and they are known for their limited and exclusive ...

  • web:www.thodex.com

    Mitigation and Remediation Techniques To mitigate the threat of RansomEXX , organizations must focus on employee education to recognize and avoid phishing attempts. Implementing strong password policies and enabling multi-factor authentication (MFA) are critical steps in securing access points.

  • web:www.trendmicro.com

    RansomEXX campaigns, as typical of Gold Dupont attacks, involve malware like Vatet Loader, PyXie RAT, TrickBot, and post-intrusion tools like Cobalt Strike as part of their arsenal. The use of trojanized legitimate tools is common among modern ransomware variants, allowing them to deploy payloads faster while avoiding detection.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.