s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.rotajakiro

📛 Threat Title

Malware family: RotaJakiro

Category: RotaJakiro First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.rotajakiro`. Printable name: RotaJakiro.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.rotajakiro VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.rotajakiro

IOC database

Type
domain
Value
elf.rotajakiro
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.rotajakiro

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.rotajakiro

References (1)

Remediations (10)

  • web:any.run

    Online sandbox report for RotaJakiro . malware , verdict: Malicious activity

  • web:attack.mitre.org

    RotaJakiro is a 64-bit Linux backdoor used by APT32. First seen in 2018, it uses a plugin architecture to extend capabilities. RotaJakiro can determine it's permission level and execute according to access type (root or user). [1] [2]

  • web:cve.nohackme.com

    RotaJakiro is a 64-bit Linux backdoor used by APT32. First seen in 2018, it uses a plugin architecture to extend capabilities. RotaJakiro can determine it's permission level and execute according to access type (`root` or `user`). Platforms : Linux Version : 1.0 Created : 14 June 2023 Last Modified : 12 October 2023

  • web:cybersecuritynews.com

    Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.

  • web:malpedia.caad.fkie.fraunhofer.de

    RotaJakiro is a stealthy Linux backdoor which remained undetected between 2018 and 2021. The malware uses rotating encryption to encrypt the resource information within the sample, and C2 communication, using a combination of AES, XOR, ROTATE encryption and ZLIB compression.

  • web:medium.com

    RotaJakiro Writeup — Cyberdefenders' Lab RotaJakiro | Blue team challenge. RotaJakiro is a blue team lab that falls under the Malware Analysis category and will cover the following …

  • web:support.trellix.com

    Summary Description of Campaign RotaJikaro has recently been identified as a backdoor malware targeting 64-bit Linux systems. Although RotaJikaro was first submitted to VirusTotal in 2018, it has remained mostly undetected until recently. It has been found to target device information, steal sensitive data, conduct file and Plugin management, as well as execute additional Plugins received from ...

  • web:www.fortinet.com

    FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.

  • web:www.joesandbox.com

    General Information Sample name: RotaJakiro . malware Analysis ID: 1658086 MD5: 65f5b913b7fa46d907e797d1f202817d SHA1: e40103d547fd9ff45529f160a537abb3bd7ebbd4 SHA256 ...

  • web:www.trendmicro.com

    This Backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.It executes commands from a remote malicious user, effectively compromising the affected system.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.