TF-MAL-elf.rotajakiro
📛 Threat Title
Malware family: RotaJakiro
Description
ThreatFox malware family `elf.rotajakiro`. Printable name: RotaJakiro.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.rotajakiro
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.rotajakiro
IOC database
- Type
- domain
- Value
elf.rotajakiro- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.rotajakiro
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.rotajakiro
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:any.run
Online sandbox report for RotaJakiro . malware , verdict: Malicious activity
-
web:attack.mitre.org
RotaJakiro is a 64-bit Linux backdoor used by APT32. First seen in 2018, it uses a plugin architecture to extend capabilities. RotaJakiro can determine it's permission level and execute according to access type (root or user). [1] [2]
-
web:cve.nohackme.com
RotaJakiro is a 64-bit Linux backdoor used by APT32. First seen in 2018, it uses a plugin architecture to extend capabilities. RotaJakiro can determine it's permission level and execute according to access type (`root` or `user`). Platforms : Linux Version : 1.0 Created : 14 June 2023 Last Modified : 12 October 2023
-
web:cybersecuritynews.com
Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.
-
web:malpedia.caad.fkie.fraunhofer.de
RotaJakiro is a stealthy Linux backdoor which remained undetected between 2018 and 2021. The malware uses rotating encryption to encrypt the resource information within the sample, and C2 communication, using a combination of AES, XOR, ROTATE encryption and ZLIB compression.
-
web:medium.com
RotaJakiro Writeup — Cyberdefenders' Lab RotaJakiro | Blue team challenge. RotaJakiro is a blue team lab that falls under the Malware Analysis category and will cover the following …
-
web:support.trellix.com
Summary Description of Campaign RotaJikaro has recently been identified as a backdoor malware targeting 64-bit Linux systems. Although RotaJikaro was first submitted to VirusTotal in 2018, it has remained mostly undetected until recently. It has been found to target device information, steal sensitive data, conduct file and Plugin management, as well as execute additional Plugins received from ...
-
web:www.fortinet.com
FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.
-
web:www.joesandbox.com
General Information Sample name: RotaJakiro . malware Analysis ID: 1658086 MD5: 65f5b913b7fa46d907e797d1f202817d SHA1: e40103d547fd9ff45529f160a537abb3bd7ebbd4 SHA256 ...
-
web:www.trendmicro.com
This Backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.It executes commands from a remote malicious user, effectively compromising the affected system.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.