s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.saltwater

📛 Threat Title

Malware family: SALTWATER

Category: SALTWATER First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.saltwater`. Printable name: SALTWATER.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.saltwater VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.saltwater

IOC database

Type
domain
Value
elf.saltwater
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.saltwater

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.saltwater

References (1)

Remediations (10)

  • web:blog.netmanageit.com

    Description CISA obtained five malware samples - including artifacts related to SUBMARINE, SKIPJACK, SEASPRAY, WHIRLPOOL, and SALTWATER backdoors.

  • web:cybergeeks.tech

    Summary SALTWATER is a backdoor that has been used in the exploitation of the Barracuda 0-day vulnerability CVE-2023-2868. It is a module for the Barracuda SMTP daemon called bsmtpd. The malware hooked the recv, send, and close functions using an open-source hooking library called funchook.

  • web:dailysecurityreview.com

    Chinese state-sponsored hackers, the Salt Typhoon group, used custom malware , JumbledPath, to infiltrate US telecom networks, stealing data and monitoring communications.

  • web:hivepro.com

    Their arsenal of malware includes ShadowPad, a modular backdoor frequently used for persistent access; Spyder, an encrypted communication tool for post-compromise activities; and SodaMaster, a backdoor used for data extraction and remote command execution.

  • web:malpedia.caad.fkie.fraunhofer.de

    SALTWATER can upload or download arbitrary files, execute commands, and has proxy and tunneling capabilities. The backdoor is implemented using hooks on the send, recv, close syscalls via the 3rd party kubo/funchook hooking library, and amounts to five components, most of which are referred to as "Channels" within the binary.

  • web:windowsforum.com

    The emergence of RESURGE signals more than just another entry in a long line of malware threats. According to CISA, RESURGE contains advanced persistence features inherited from the SPAWNCHIMERA malware family—a group notorious for its ability to survive system reboots and avoid simplistic remediation .

  • web:www.beyondidentity.com

    Salt Typhoon is using "JumbledPath" malware to infiltrate US telecom networks. Learn how this attack is deployed and what mitigation strategies work.

  • web:www.cisa.gov

    The authoring agencies strongly urge network defenders to hunt for malicious activity and to apply the mitigations in this CSA to reduce the threat of Chinese state-sponsored and other malicious cyber activity.

  • web:www.controleng.com

    Salt Typhoon insights Understand what Salt Typhoon hack is, impact and CISA's mitigation suggestions. Review CISA cybersecurity roles and the 16 critical infrastructure sections. Assess what CISA resources you or your organization could to lower cybersecurity risk. Salt Typhoon telecommunication hack is an ongoing exploitation of AT&T, Lumen, T-Mobile, Verizon and other networks, from a ...

  • web:www.ncsc.gov.uk

    This guidance helps private and public sector organisations deal with the effects of malware (which includes ransomware). It provides actions to help organisations prevent a malware infection, and also steps to take if you're already infected. Following this guidance will reduce: the likelihood of becoming infected the spread of malware throughout your organisation the impact of the infection

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.