s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.hadooken

📛 Threat Title

Malware family: Hadooken

Category: Hadooken First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.hadooken`. Printable name: Hadooken.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.hadooken VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.hadooken

IOC database

Type
domain
Value
elf.hadooken
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.hadooken

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.hadooken

References (1)

Remediations (10)

  • web:blog.sekoia.io

    Discover the details of the K4Spreader and Hadooken malware attack chain targeting WebLogic servers, with their connection to the 8220 Gang.

  • web:cybersecsentinel.com

    The Hadooken Malware is a significant threat to enterprises running Oracle WebLogic servers. Its combination of cryptomining, DDoS botnet capabilities, and potential ransomware connections makes it a high-risk threat.

  • web:cybersecuritynews.com

    Aqua Nautilus researchers discovered that a new Linux malware dubbed " Hadooken ," has been actively exploiting Oracle Weblogic servers.

  • web:linuxsecurity.com

    Fortify your system from Hadooken threats through effective detection, mitigation techniques, and essential guidelines for Linux administrators.

  • web:malleum.com

    Aqua Nautilus researchers identified a new Linux malware targeting Weblogic servers. The main payload calls itself Hadooken , a potential reference to the Hadouken attack (or "surge fist") in the Street Fighter video game series. When Hadooken is executed, it drops a Tsunami malware and deploys a cryptominer. In this article, we explain the malware , its components, and how it was detected.

  • web:threats.wiz.io

    Researchers discovered a new Linux malware named " Hadooken " that specifically targets Oracle WebLogic servers. The malware exploits weak passwords to gain access and then deploys both Tsunami malware and a cryptominer. The attack flow involves using a combination of shell and Python scripts to download and execute the Hadooken malware , iterating over SSH data to move laterally within the ...

  • web:www.aquasec.com

    The Hadooken malware itself contains both a cryptominer and Tsunami malware . When Hadooken malware is executed, it drops two elf files. The first file is a packed cryptominer (MD5: b9f096559e923787ebb1288c93ce2902) dropped into 3 paths under 3 different names: '/usr/bin/crondr ', '/usr/bin/bprofr' and '/mnt/-java'.

  • web:www.attackiq.com

    Discovery & Defense Evasion - Hadooken Malware Deployment Click for larger This stage performs the deployment of the Hadooken malware and follow-up discovery and defense evasion activities. Once executed, Hadooken begins collecting system information such as the current user context, operating system type, and mounted filesystems.

  • web:www.darkreading.com

    A threat actor is dropping a cryptominer and distributed denial-of-service (DDoS) malware on Oracle WebLogic Servers using " Hadooken ." Researchers at Aqua Nautilus spotted the malware when it hit ...

  • web:www.securityweek.com

    A new Linux malware has been observed targeting Oracle WebLogic servers to deploy additional malware and extract credentials for lateral movement, Aqua Security's Nautilus research team warns. Called Hadooken , the malware is deployed in attacks that exploit weak passwords for initial access.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.