s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.sustes

📛 Threat Title

Malware family: sustes miner

Category: sustes miner First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.sustes`. Printable name: sustes miner.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.sustes VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.sustes

IOC database

Type
domain
Value
elf.sustes
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.sustes

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.sustes

References (1)

Remediations (10)

  • web:cybernews.com

    The FBI warns of a surge in ATM jackpotting attacks, with more than 700 incidents in 2025 alone. Hackers use Ploutus malware to force machines to dispense cash.

  • web:gist.github.com

    Save Istriaeee/403ffd37de7f1293face48917d18e81c to your computer and use it in GitHub Desktop.

  • web:knowledge.broadcom.com

    Destructive forms of malware function using similar methods as coinminers. Eradicating miners and strengthening your network's defenses will help prevent other threats.

  • web:learn.microsoft.com

    Since coin miners are becoming a popular payload in many different kinds of attacks, see general tips on how to prevent malware infection. For more information on coin miners , see the blog post Invisible resource thieves: The increasing threat of cryptocurrency miners . Was this page helpful?

  • web:malpedia.caad.fkie.fraunhofer.de

    Sustes Malware doesn't infect victims by itself (it's not a worm) but it is spread over exploitation and brute-force activities with special focus on IoT and Linux servers. The initial infection stage comes from a custom wget directly on the victim machine followed by a simple /bin/bash mr.sh. The script is a simple bash script which drops and executes additional software.

  • web:malwaretips.com

    Watch for PowerShell spawning unexpected network activity or miner -related behavior. Conclusion The campaign is worth discussing, but the strongest accurate wording is that the report appears to describe malware with indicators of AI-assisted development, not proven "AI-written malware " in an absolute sense.

  • web:success.trendmicro.com

    Coinminer.Win64.MALXMR is a cryptocurrency-mining malware which exploited EternalBlue for propagation and abused Windows Management Instrumentation (WMI) for persistence. It uses the system's central processing unit (CPU) and/or graphical processing unit (GPU) resources to mine cryptocurrency. The following can be observed during the infection: High CPU Utilization either with powershell.exe ...

  • web:support.norton.com

    However, malware authors have created threats and viruses which use commonly-available mining software to take advantage of someone else's computing resources (CPU, GPU, RAM, network bandwidth, and power), without their knowledge or consent (i.e. cryptojacking).

  • web:www.cyfirma.com

    The GhostGrab malware family is a prime example of this evolution. This report provides a technical deep-dive into GhostGrab, a modular Android stealer and clandestine miner .

  • web:www.malwarebytes.com

    Click Quarantine to remove the found threats. Reboot the system if prompted to complete the removal process. Business remediation How to remove Trojan.CoinMiner with the Malwarebytes Nebula console You can use the Malwarebytes Anti- Malware Nebula console to scan endpoints. Nebula endpoint tasks menu Choose the Scan + Quarantine option.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.