TF-MAL-elf.blackmatter
📛 Threat Title
Malware family: BlackMatter
Description
ThreatFox malware family `elf.blackmatter`. Printable name: BlackMatter.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.blackmatter
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.blackmatter
IOC database
- Type
- domain
- Value
elf.blackmatter- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.blackmatter
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.blackmatter
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:any.run
BlackMatter is a fast-moving ransomware strain that encrypts local and network data, disables recovery mechanisms, and forces organizations into multimillion-dollar ransom demands.
-
web:complexdiscovery.com
This advisory provides information on cyber actor tactics, techniques, and procedures (TTPs) obtained from a sample of BlackMatter ransomware analyzed in a sandbox environment as well from trusted third-party reporting. Using embedded, previously compromised credentials, BlackMatter leverages the Lightweight Directory Access Protocol (LDAP) and Server Message Block (SMB) protocol to access the ...
-
web:media.defense.gov
This advisory provides information on cyber actor tactics, techniques, and procedures (TTPs) obtained from a sample of BlackMatter ransomware analyzed in a sandbox environment as well from trusted third-party reporting. Using embedded, previously compromised credentials, BlackMatter leverages the Lightweight Directory Access Protocol (LDAP) and Server Message Block (SMB) protocol to access the ...
-
web:www.cisa.gov
SUMMARY This joint Cybersecurity Advisory was developed by the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) to provide information on BlackMatter ransomware. Since July 2021, BlackMatter ransomware has targeted multiple U.S. critical infrastructure entities, including two U.S. Food and Agriculture ...
-
web:www.datatechguard.com
Join us as we delve into BlackMatter Ransomware Analysis, uncovering its mechanisms and threats to protect your networks and data. Stay safe with us!
-
web:www.hhs.gov
What the Group Claims to Be Sources include an interview with a BlackMatter representative, the BlackMatter Ransomware public extortion blog, hacking forum advertisements, affiliate panel information, and ransom notes.
-
web:www.nsa.gov
The advisory includes technical details, analysis, and assessment of this cyber threat, as well as several mitigation actions that can be taken to reduce the risk to this ransomware.
-
web:www.picussecurity.com
We analyzed tactics, techniques, and procedures utilized by the BlackMatter Ransomware Group to understand their attacks and the impact of the ransomware.
-
web:www.sentinelone.com
BlackMatter Ransomware Technical Details Current versions of BlackMatter exist for both Windows and Linux operating systems. However, the malware is highly obfuscated and employs numerous anti-analysis techniques. In addition, the authors have enhanced the ransomware with advanced features, such as the ability to infect systems even when in safe mode, thus circumventing certain antivirus products.
-
web:www.varonis.com
CISA has issued a security bulletin regarding the BlackMatter 'big game hunter' ransomware group following a sharp increase in cases targeting U.S. businesses. To mitigate these attacks, it is recommended...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.