s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.fbot

📛 Threat Title

Malware family: FBot

Category: FBot First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.fbot`. Printable name: FBot.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.fbot VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.fbot

IOC database

Type
domain
Value
elf.fbot
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.fbot

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.fbot

References (1)

Remediations (10)

  • web:blog.malwaremustdie.org

    Mirai FBOT re-emerging botnet Linux malware , aims Linux basis IoT devices for DDoS attacks and malicious traffic distribution

  • web:blog.netmanageit.com

    Description FBot is a Python-based hacking tool distinct from other cloud malware families, targeting web servers, cloud services, and SaaS platforms like AWS, Ofice365, PayPal, Sendgrid, and Twilio. FBot does not utilize the widely-used Androxgh0st code but shares similarities with the Legion cloud infostealer in functionality and design.Key features include credential harvesting for spamming ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the FBot malware family including references, samples and yara signatures.

  • web:securityaffairs.com

    We have learned much experience from the Mirai Fbot re-emerging case. What seems to be the end of a botnet can be a sign of a new beginning, and also by working together we can control IoT malware infection into a very minimum level. If the motivation, bad actors and the target are there, the same threat could rise again, and again.

  • web:siliconangle.com

    Dubbed " FBot ," the malware is said to represent a significant threat due to its specific targeting of web servers, cloud services and software-as-a-service platforms, including Amazon Web ...

  • web:www.globalsecuritymag.com

    FBot is primarily designed for actors to hijack cloud, SaaS, and web services. There is a secondary focus on obtaining accounts to conduct spamming attacks. Actors can use the credential harvesting features to obtain initial access, which they can sell to other parties. Key points FBot is a Python-based hacking tool distinct from other cloud malware families, targeting web servers, cloud ...

  • web:www.infosecurity-magazine.com

    Security researchers have shed light on a new Python-based hacking tool, FBot , showcasing distinct features from other cloud malware families. Discovered by the SentinelLabs team, FBot targets web servers, cloud services and Software-as-a-Service (SaaS) platforms like AWS, Office365, PayPal, Sendgrid and Twilio.

  • web:www.researchgate.net

    FBot , a sophisticated Python-based malware , poses a significant threat to cloud services and payment systems. This article explores its architecture, capabilities, and operational patterns ...

  • web:www.scworld.com

    Microsoft Office 365, Amazon Web Services, PayPal, Twilio, and other cloud and software-as-a-service platforms are being targeted by the novel FBot malware based on the Python programming language, reports SiliconAngle.

  • web:www.sentinelone.com

    Executive Summary FBot is a Python-based hacking tool distinct from other cloud malware families, targeting web servers, cloud services, and SaaS platforms like AWS, Office365, PayPal, Sendgrid, and Twilio. FBot does not utilize the widely-used Androxgh0st code but shares similarities with the Legion cloud infostealer in functionality and design. Key features include credential harvesting for ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.