TF-MAL-elf.fbot
📛 Threat Title
Malware family: FBot
Description
ThreatFox malware family `elf.fbot`. Printable name: FBot.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.fbot
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.fbot
IOC database
- Type
- domain
- Value
elf.fbot- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.fbot
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.fbot
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.malwaremustdie.org
Mirai FBOT re-emerging botnet Linux malware , aims Linux basis IoT devices for DDoS attacks and malicious traffic distribution
-
web:blog.netmanageit.com
Description FBot is a Python-based hacking tool distinct from other cloud malware families, targeting web servers, cloud services, and SaaS platforms like AWS, Ofice365, PayPal, Sendgrid, and Twilio. FBot does not utilize the widely-used Androxgh0st code but shares similarities with the Legion cloud infostealer in functionality and design.Key features include credential harvesting for spamming ...
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the FBot malware family including references, samples and yara signatures.
-
web:securityaffairs.com
We have learned much experience from the Mirai Fbot re-emerging case. What seems to be the end of a botnet can be a sign of a new beginning, and also by working together we can control IoT malware infection into a very minimum level. If the motivation, bad actors and the target are there, the same threat could rise again, and again.
-
web:siliconangle.com
Dubbed " FBot ," the malware is said to represent a significant threat due to its specific targeting of web servers, cloud services and software-as-a-service platforms, including Amazon Web ...
-
web:www.globalsecuritymag.com
FBot is primarily designed for actors to hijack cloud, SaaS, and web services. There is a secondary focus on obtaining accounts to conduct spamming attacks. Actors can use the credential harvesting features to obtain initial access, which they can sell to other parties. Key points FBot is a Python-based hacking tool distinct from other cloud malware families, targeting web servers, cloud ...
-
web:www.infosecurity-magazine.com
Security researchers have shed light on a new Python-based hacking tool, FBot , showcasing distinct features from other cloud malware families. Discovered by the SentinelLabs team, FBot targets web servers, cloud services and Software-as-a-Service (SaaS) platforms like AWS, Office365, PayPal, Sendgrid and Twilio.
-
web:www.researchgate.net
FBot , a sophisticated Python-based malware , poses a significant threat to cloud services and payment systems. This article explores its architecture, capabilities, and operational patterns ...
-
web:www.scworld.com
Microsoft Office 365, Amazon Web Services, PayPal, Twilio, and other cloud and software-as-a-service platforms are being targeted by the novel FBot malware based on the Python programming language, reports SiliconAngle.
-
web:www.sentinelone.com
Executive Summary FBot is a Python-based hacking tool distinct from other cloud malware families, targeting web servers, cloud services, and SaaS platforms like AWS, Office365, PayPal, Sendgrid, and Twilio. FBot does not utilize the widely-used Androxgh0st code but shares similarities with the Legion cloud infostealer in functionality and design. Key features include credential harvesting for ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.