TF-MAL-elf.ransomexx
📛 Threat Title
Malware family: RansomEXX
Description
ThreatFox malware family `elf.ransomexx`. Printable name: RansomEXX. Aliases: Defray777.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.ransomexx
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.ransomexx
IOC database
- Type
- domain
- Value
elf.ransomexx- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.ransomexx
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.ransomexx
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:kcm.trellix.com
Our Threat Research team will continue to monitor and update the RansomEXX ransomware profile and disseminate information that is deemed appropriate regarding the RansomEXX ransomware and victims. How to use this article: If a Threat Hunting table has been created, use the rules contained to search for malware related to this campaign.
-
web:malpedia.caad.fkie.fraunhofer.de
RansomExx is a ransomware family that targeted multiple companies starting in mid-2020. It shares commonalities with Defray777.
-
web:rasoc.ae
Introduction: RansomEXX , also known as Defray or Defray777, is a multifaceted ransomware threat that emerged in late 2020. This analysis provides an in-depth exploration of RansomEXX Ransomware, covering its background, target sectors, modus operandi, technical intricacies, detection methods, mitigation strategies, and removal procedures. RansomEXX Ransomware Overview: Emergence: First ...
-
web:us.quickheal.com
RansomExx is an apt example of how a ransomware family can evolve in finding new ways of infecting machines. The new variant compared to Defray777 shows that the threat actors are improvising with sophisticated modern methods to evade detection by running file-less malware and using advanced intrusion techniques combined with anti-forensic ...
-
web:www.ibm.com
RansomExx is operated by the DefrayX threat actor group (Hive0091), which is also known for the PyXie malware , Vatet loader, and Defray ransomware strains. The newly discovered ransomware version is named RansomExx2 according to strings found within the ransomware and is designed to run on the Linux operating system.
-
web:www.ransomlook.io
Description RansomExx is a ransomware family that targeted multiple companies starting in mid-2020. It shares commonalities with Defray777.
-
web:www.ransomware.live
RansomExx is a ransomware family that targeted multiple companies starting in mid-2020. It shares commonalities with Defray777.
-
web:www.sentinelone.com
What is RansomEXX Ransomware? RansomEXX (aka Defray, Defray777), a multi-pronged extortion threat, has been observed in the wild since late 2020. RansomEXX is associated with attacks against the Texas Department of Transportation, Groupe Atlantic, and several other large enterprises. There are Windows and Linux variants of this malware family , and they are known for their limited and exclusive ...
-
web:www.thodex.com
Mitigation and Remediation Techniques To mitigate the threat of RansomEXX , organizations must focus on employee education to recognize and avoid phishing attempts. Implementing strong password policies and enabling multi-factor authentication (MFA) are critical steps in securing access points.
-
web:www.trendmicro.com
RansomEXX campaigns, as typical of Gold Dupont attacks, involve malware like Vatet Loader, PyXie RAT, TrickBot, and post-intrusion tools like Cobalt Strike as part of their arsenal. The use of trojanized legitimate tools is common among modern ransomware variants, allowing them to deploy payloads faster while avoiding detection.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.