s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.gotitan

📛 Threat Title

Malware family: GoTitan

Category: GoTitan First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.gotitan`. Printable name: GoTitan.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.gotitan VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.gotitan

IOC database

Type
domain
Value
elf.gotitan
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.gotitan

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.gotitan

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    Despite a patch released over a month ago, threat actors persist in exploiting CVE-2023-46604, perpetuating the distribution of malware via vulnerable servers. Notably, the emergence of GoTitan , PrCtrl Rat, and the ongoing exploits by Sliver, Kinsing, and Ddostf signify the persistent and evolving threat landscape surrounding this vulnerability.

  • web:blog.netmanageit.com

    Description An ongoing exploitation of a critical Apache ActiveMQ vulnerability has led to the emergence of two new strains of malware , including GoTitan and Ddostf, according to Fortiguard Labs.

  • web:cybersecuritynews.com

    GoTitan Botnet - Ongoing Exploitation on Apache ActiveMQ Generally, in this case, the attacker causes the system to unmarshal a class under their control by sending a crafted packet.

  • web:hackread.com

    Researchers claim that this flaw is currently being exploited to distribute various malware strains, including GoTitan , PrCtrl Rat, Kinsing, Silver, and Ddostff. Silver, designed as an advanced penetration testing tool and red teaming framework, has the capability to support various callback protocols, including TCP, DNS, and HTTP (S).

  • web:redskyalliance.org

    In the following sections, analysts will explain how the malware works and what it does on infected systems. Figure 1: Attacking traffic for CVE-2023-46604 Figure 2: Malicious XML files Figure 3: GoTitan's XML file GoTitan is a new botnet discovered earlier this month.

  • web:thehackernews.com

    Fortinet said it also observed instances where the susceptible Apache ActiveMQ servers are being targeted to deploy another DDoS botnet called Ddostf, Kinsing malware for cryptojacking, and a command-and-control (C2) framework named Sliver. Another notable malware delivered is a remote access trojan dubbed PrCtrl Rat that establishes contact with a C2 server to receive additional commands for ...

  • web:threats.wiz.io

    Fortiguard Labs detected numerous threat actors exploiting CVE-2023-46604 to disseminate diverse strains of malware . Their analysis unveiled the emergence of a newly discovered Golang-based botnet named GoTitan and a .NET program called "PrCtrl Rat," equipped with remote control capabilities.

  • web:www.cybersecurity-review.com

    This past October, Apache issued a critical advisory addressing CVE-2023-46604, a vulnerability involving the deserialization of untrusted data in Apache.

  • web:www.fortinet.com

    In recent weeks, Fortiguard Labs has detected numerous threat actors exploiting CVE-2023-46604 to disseminate diverse strains of malware . Our analysis has unveiled the emergence of a newly discovered Golang-based botnet named GoTitan and a .NET program called "PrCtrl Rat," equipped with remote control capabilities.

  • web:www.infosecurity-magazine.com

    GoTitan has been observed downloading from a malicious URL and exhibits a specific focus on x64 architectures. Furthermore, the malware , while still in an early stage of development, replicates itself within systems, establishes recurring execution through cron registration and collects essential information about compromised endpoints.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Reputation of linked indicators

DomScan scores the domains, AbuseIPDB + GreyNoise score the IPs. Verdicts are per-indicator — this is a roll-up, so no lookup is triggered by opening this page.

Domains scored
1 / 1
IPs scored
0 / 0
Flagged
1
IndicatorTypeVerdictScore
elf.gotitan domain high 44