TF-MAL-elf.sustes
📛 Threat Title
Malware family: sustes miner
Description
ThreatFox malware family `elf.sustes`. Printable name: sustes miner.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.sustes
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.sustes
IOC database
- Type
- domain
- Value
elf.sustes- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.sustes
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.sustes
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybernews.com
The FBI warns of a surge in ATM jackpotting attacks, with more than 700 incidents in 2025 alone. Hackers use Ploutus malware to force machines to dispense cash.
-
web:gist.github.com
Save Istriaeee/403ffd37de7f1293face48917d18e81c to your computer and use it in GitHub Desktop.
-
web:knowledge.broadcom.com
Destructive forms of malware function using similar methods as coinminers. Eradicating miners and strengthening your network's defenses will help prevent other threats.
-
web:learn.microsoft.com
Since coin miners are becoming a popular payload in many different kinds of attacks, see general tips on how to prevent malware infection. For more information on coin miners , see the blog post Invisible resource thieves: The increasing threat of cryptocurrency miners . Was this page helpful?
-
web:malpedia.caad.fkie.fraunhofer.de
Sustes Malware doesn't infect victims by itself (it's not a worm) but it is spread over exploitation and brute-force activities with special focus on IoT and Linux servers. The initial infection stage comes from a custom wget directly on the victim machine followed by a simple /bin/bash mr.sh. The script is a simple bash script which drops and executes additional software.
-
web:malwaretips.com
Watch for PowerShell spawning unexpected network activity or miner -related behavior. Conclusion The campaign is worth discussing, but the strongest accurate wording is that the report appears to describe malware with indicators of AI-assisted development, not proven "AI-written malware " in an absolute sense.
-
web:success.trendmicro.com
Coinminer.Win64.MALXMR is a cryptocurrency-mining malware which exploited EternalBlue for propagation and abused Windows Management Instrumentation (WMI) for persistence. It uses the system's central processing unit (CPU) and/or graphical processing unit (GPU) resources to mine cryptocurrency. The following can be observed during the infection: High CPU Utilization either with powershell.exe ...
-
web:support.norton.com
However, malware authors have created threats and viruses which use commonly-available mining software to take advantage of someone else's computing resources (CPU, GPU, RAM, network bandwidth, and power), without their knowledge or consent (i.e. cryptojacking).
-
web:www.cyfirma.com
The GhostGrab malware family is a prime example of this evolution. This report provides a technical deep-dive into GhostGrab, a modular Android stealer and clandestine miner .
-
web:www.malwarebytes.com
Click Quarantine to remove the found threats. Reboot the system if prompted to complete the removal process. Business remediation How to remove Trojan.CoinMiner with the Malwarebytes Nebula console You can use the Malwarebytes Anti- Malware Nebula console to scan endpoints. Nebula endpoint tasks menu Choose the Scan + Quarantine option.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.