TF-MAL-elf.gotitan
📛 Threat Title
Malware family: GoTitan
Description
ThreatFox malware family `elf.gotitan`. Printable name: GoTitan.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.gotitan
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.gotitan
IOC database
- Type
- domain
- Value
elf.gotitan- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.gotitan
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.gotitan
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
Despite a patch released over a month ago, threat actors persist in exploiting CVE-2023-46604, perpetuating the distribution of malware via vulnerable servers. Notably, the emergence of GoTitan , PrCtrl Rat, and the ongoing exploits by Sliver, Kinsing, and Ddostf signify the persistent and evolving threat landscape surrounding this vulnerability.
-
web:blog.netmanageit.com
Description An ongoing exploitation of a critical Apache ActiveMQ vulnerability has led to the emergence of two new strains of malware , including GoTitan and Ddostf, according to Fortiguard Labs.
-
web:cybersecuritynews.com
GoTitan Botnet - Ongoing Exploitation on Apache ActiveMQ Generally, in this case, the attacker causes the system to unmarshal a class under their control by sending a crafted packet.
-
web:hackread.com
Researchers claim that this flaw is currently being exploited to distribute various malware strains, including GoTitan , PrCtrl Rat, Kinsing, Silver, and Ddostff. Silver, designed as an advanced penetration testing tool and red teaming framework, has the capability to support various callback protocols, including TCP, DNS, and HTTP (S).
-
web:redskyalliance.org
In the following sections, analysts will explain how the malware works and what it does on infected systems. Figure 1: Attacking traffic for CVE-2023-46604 Figure 2: Malicious XML files Figure 3: GoTitan's XML file GoTitan is a new botnet discovered earlier this month.
-
web:thehackernews.com
Fortinet said it also observed instances where the susceptible Apache ActiveMQ servers are being targeted to deploy another DDoS botnet called Ddostf, Kinsing malware for cryptojacking, and a command-and-control (C2) framework named Sliver. Another notable malware delivered is a remote access trojan dubbed PrCtrl Rat that establishes contact with a C2 server to receive additional commands for ...
-
web:threats.wiz.io
Fortiguard Labs detected numerous threat actors exploiting CVE-2023-46604 to disseminate diverse strains of malware . Their analysis unveiled the emergence of a newly discovered Golang-based botnet named GoTitan and a .NET program called "PrCtrl Rat," equipped with remote control capabilities.
-
web:www.cybersecurity-review.com
This past October, Apache issued a critical advisory addressing CVE-2023-46604, a vulnerability involving the deserialization of untrusted data in Apache.
-
web:www.fortinet.com
In recent weeks, Fortiguard Labs has detected numerous threat actors exploiting CVE-2023-46604 to disseminate diverse strains of malware . Our analysis has unveiled the emergence of a newly discovered Golang-based botnet named GoTitan and a .NET program called "PrCtrl Rat," equipped with remote control capabilities.
-
web:www.infosecurity-magazine.com
GoTitan has been observed downloading from a malicious URL and exhibits a specific focus on x64 architectures. Furthermore, the malware , while still in an early stage of development, replicates itself within systems, establishes recurring execution through cron registration and collects essential information about compromised endpoints.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Reputation of linked indicators
DomScan scores the domains, AbuseIPDB + GreyNoise score the IPs. Verdicts are per-indicator — this is a roll-up, so no lookup is triggered by opening this page.
| Indicator | Type | Verdict | Score |
|---|---|---|---|
elf.gotitan |
domain | high | 44 |