s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.blackmatter

📛 Threat Title

Malware family: BlackMatter

Category: BlackMatter First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.blackmatter`. Printable name: BlackMatter.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.blackmatter VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.blackmatter

IOC database

Type
domain
Value
elf.blackmatter
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.blackmatter

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.blackmatter

References (1)

Remediations (10)

  • web:any.run

    BlackMatter is a fast-moving ransomware strain that encrypts local and network data, disables recovery mechanisms, and forces organizations into multimillion-dollar ransom demands.

  • web:complexdiscovery.com

    This advisory provides information on cyber actor tactics, techniques, and procedures (TTPs) obtained from a sample of BlackMatter ransomware analyzed in a sandbox environment as well from trusted third-party reporting. Using embedded, previously compromised credentials, BlackMatter leverages the Lightweight Directory Access Protocol (LDAP) and Server Message Block (SMB) protocol to access the ...

  • web:media.defense.gov

    This advisory provides information on cyber actor tactics, techniques, and procedures (TTPs) obtained from a sample of BlackMatter ransomware analyzed in a sandbox environment as well from trusted third-party reporting. Using embedded, previously compromised credentials, BlackMatter leverages the Lightweight Directory Access Protocol (LDAP) and Server Message Block (SMB) protocol to access the ...

  • web:www.cisa.gov

    SUMMARY This joint Cybersecurity Advisory was developed by the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) to provide information on BlackMatter ransomware. Since July 2021, BlackMatter ransomware has targeted multiple U.S. critical infrastructure entities, including two U.S. Food and Agriculture ...

  • web:www.datatechguard.com

    Join us as we delve into BlackMatter Ransomware Analysis, uncovering its mechanisms and threats to protect your networks and data. Stay safe with us!

  • web:www.hhs.gov

    What the Group Claims to Be Sources include an interview with a BlackMatter representative, the BlackMatter Ransomware public extortion blog, hacking forum advertisements, affiliate panel information, and ransom notes.

  • web:www.nsa.gov

    The advisory includes technical details, analysis, and assessment of this cyber threat, as well as several mitigation actions that can be taken to reduce the risk to this ransomware.

  • web:www.picussecurity.com

    We analyzed tactics, techniques, and procedures utilized by the BlackMatter Ransomware Group to understand their attacks and the impact of the ransomware.

  • web:www.sentinelone.com

    BlackMatter Ransomware Technical Details Current versions of BlackMatter exist for both Windows and Linux operating systems. However, the malware is highly obfuscated and employs numerous anti-analysis techniques. In addition, the authors have enhanced the ransomware with advanced features, such as the ability to infect systems even when in safe mode, thus circumventing certain antivirus products.

  • web:www.varonis.com

    CISA has issued a security bulletin regarding the BlackMatter 'big game hunter' ransomware group following a sharp increase in cases targeting U.S. businesses. To mitigate these attacks, it is recommended...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.