s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.fritzfrog

📛 Threat Title

Malware family: FritzFrog

Category: FritzFrog First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.fritzfrog`. Printable name: FritzFrog.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.fritzfrog VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.fritzfrog

IOC database

Type
domain
Value
elf.fritzfrog
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.fritzfrog

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.fritzfrog

References (1)

Remediations (10)

  • web:blog.gridinsoft.com

    Researchers detected a new sample of FritzFrog malware , that is known for creating significant botnets. The new threat sample includes the functionality to exploit flaws in network assets, including the infamous Log4Shell vulnerability. As it turns out, even 2 years past the discovery and feverish updating, there are quite a few instances vulnerable to such attacks. FritzFrog Botnet is Back ...

  • web:blog.netmanageit.com

    Description The Akamai Security Intelligence Group (SIG) has uncovered details about a new variant of the FritzFrog botnet, which abuses the 2021 Log4Shell vulnerability. Over the years we have seen more than 20,000 FritzFrog attacks, and 1,500+ victims. The malware infects internet-facing servers by brute forcing weak SSH credentials. Newer variants now read several system files on ...

  • web:cybernoz.com

    The FritzFrog cryptomining botnet has new potential for growth: a recently analyzed variant of the bot is exploiting the Log4Shell (CVE-2021-44228) and PwnKit (CVE-2021-4034) vulnerabilities for lateral movement and privilege escalation. The FritzFrog botnet The FritzFrog botnet, initially identified in August 2020, is a peer-to-peer (rather than centrally-controlled) botnet powered by malware ...

  • web:en.linuxadictos.com

    Guardicore (a cloud and data center security company) has identified new malware high-tech, called " FritzFrog ", which affects Linux-based servers. FritzFrog combines a worm that is spread through a brute force attack on servers with an open SSH port and components to build a decentralized botnet It works without control nodes and does not have a single point of failure.

  • web:github.com

    A repository full of malware samples. Contribute to Da2dalus/The- MALWARE -Repo development by creating an account on GitHub.

  • web:infoaday.com

    The risk actor behind a peer-to-peer (P2P) botnet often called FritzFrog has made a return with a brand new variant that leverages the Log4Shell vulnerability to propagate internally inside an already compromised community. "The vulnerability is exploited in a brute-force method that makes an attempt to focus on as many susceptible Java functions as attainable," net infrastructure and ...

  • web:onlincecybersecure.com

    FritzFrog , first documented by Guardicore (now part of Akamai) in August 2020, is a Golang-based malware that primarily targets internet-facing servers with weak SSH credentials. It's known to be active since January 2020.

  • web:techempiresolutions.wordpress.com

    FritzFrog's SSH brute force component has also been improved to identify specific SSH targets by listing multiple system logs per victim. Another notable variation of the malware is the use of the PwnKit flaw CVE-2021-4034 to achieve local privilege escalation. " FritzFrog continues to employ hiding tactics to avoid detection," David said.

  • web:therecord.media

    The FritzFrog malware attempts to target all hosts in the internal network — meaning that even if the "high-profile" internet-facing applications have been patched, a breach of any asset in the network by FritzFrog can expose unpatched internal assets to exploitation, Akamai explained.

  • web:www.linkedin.com

    The Akamai Security Intelligence Group uncovered a new variant of the FritzFrog botnet leveraging the Log4Shell vulnerability, dubbed Frog4Shell. This evolution marks a significant shift in ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.