TF-MAL-elf.sshdoor
📛 Threat Title
Malware family: SSHDoor
Description
ThreatFox malware family `elf.sshdoor`. Printable name: SSHDoor.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.sshdoor
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.sshdoor
IOC database
- Type
- domain
- Value
elf.sshdoor- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.sshdoor
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.sshdoor
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as SSHDoor .
-
web:cybernews.com
The FBI warns of a surge in ATM jackpotting attacks, with more than 700 incidents in 2025 alone. Hackers use Ploutus malware to force machines to dispense cash.
-
web:github.com
Linux/ SSHDoor IoCs The following tables are the samples analyzed during our research on OpenSSH backdoors. For a full description of each family , see ESET's research paper The Dark Side of the ForSSHe available on WeLiveSecurity. A blog post summarizing our finding is also available.
-
web:halilozturkci.com
It's serious, but not Conti-level — the Conti leaks included full operational infrastructure, internal chats, affiliate payment systems across multiple malware families. This is a single malware family's construction toolkit. Russia and South Africa targeting The current data confirms India and Russia as active targets.
-
web:learn.microsoft.com
These tools can scan your system for known vulnerabilities and provide recommendations for remediation . It is important to regularly scan your system for vulnerabilities and apply security updates as soon as they become available.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the SSHDoor malware family including references, samples and yara signatures.
-
web:www.breachsense.com
Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.linkedin.com
124% surge in IoT malware attacks in 2026. That's not a gradual increase. It's an explosion. IoT malware attacks more than doubled year-over-year, with attackers recruiting millions of vulnerable ...
-
web:www.vicarius.io
🚀Vulnerable SSH configurations can expose systems to cryptographic attacks, including downgrade attacks or chosen-ciphertext attacks. This script enforces strong algorithms and disables known weak ones, aligning the configuration with modern security best practices. By removing chacha20-poly1305@openssh.com, it also allows specific exclusion scenarios, useful in advanced testing or policy ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.