s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.goreshell

📛 Threat Title

Malware family: GOREshell

Category: GOREshell First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.goreshell`. Printable name: GOREshell.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.goreshell VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.goreshell

IOC database

Type
domain
Value
elf.goreshell
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.goreshell

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.goreshell

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    The attackers employed a combination of custom malware and publicly available tools to infiltrate systems, conduct reconnaissance, and maintain persistence. Initial access vectors included exploitation of vulnerabilities in IT infrastructure and supply chain compromises via third-party logistics providers.

  • web:cybersecuritynews.com

    GoReShell Backdoor The primary backdoor deployed in these intrusions is a Go-language based malware tracked as GoReShell . This sophisticated tool establishes reverse SSH connections to attacker-controlled endpoints and leverages functionalities from the open-source reverse_ssh project.

  • web:dailysecurityreview.com

    Chinese threat actors linked to APT15 and APT41 attempted to compromise SentinelOne through a third-party logistics provider using ShadowPad and GOREshell malware in a global cyber-espionage campaign.

  • web:github.com

    Guidance for mitigation web shells. #nsacyber. Contribute to nsacyber/Mitigating-Web-Shells development by creating an account on GitHub.

  • web:hackread.com

    A key piece of malicious software was ShadowPad, described as a "closed-source modular backdoor platform" often used by these Chinese-linked groups to spy and gain remote access. Another tool, part of the GOREshell family , which includes reverse_ssh backdoor variants were also deployed. Infrastructure Overview (Source: SentinelLABS)

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the GOREshell malware family including references, samples and yara signatures.

  • web:www.broadcom.com

    The PurpleHaze malware was notably cross-platform, affecting both Windows and Linux systems. On Windows, attackers employed DLL side-loading to launch the malware . On both operating systems, the actors established C2 connections and deployed GoReShell variants to gain persistent access via reverse shells.

  • web:www.enterprisesecuritytech.com

    PurpleHaze: GOREshell and Infrastructure Masquerades Parallel to ShadowPad, a more recent cluster dubbed PurpleHaze emerged in September and October 2024. This cluster, loosely associated with APT15 and UNC5174, revealed a mix of novel malware , legitimate software repurposed for persistence, and clever use of operational relay box (ORB) networks.

  • web:www.imda.gov.sg

    Detection and Mitigation IMDA recommends organisations to perform continual testing and validating of existing security controls to ensure detection and prevention of GOREshell and ScatterBrain malware identified in this advisory:

  • web:www.sentinelone.com

    The threat actor made significant efforts to obscure their activity and remove evidence of their presence, including timestomping GOREshell executable files and deploying a log removal tool on Linux systems, specifically at the /usr/sbin/mcl filepath.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.