s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.bushwalk

📛 Threat Title

Malware family: BUSHWALK

Category: BUSHWALK First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.bushwalk`. Printable name: BUSHWALK.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.bushwalk VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bushwalk

IOC database

Type
domain
Value
elf.bushwalk
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.bushwalk

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bushwalk

References (1)

Remediations (10)

  • web:attack.mitre.org

    BUSHWALK is a web shell written in Perl that was inserted into the legitimate querymanifest.cgi file on compromised Ivanti Connect Secure VPNs during Cutting Edge.

  • web:cloud.google.com

    BUSHWALK Variant In Cutting Edge, Part 2, we introduced a new web shell tracked as BUSHWALK associated with the exploitation of CVE-2024-21893 and CVE-2024-21887. Similar to other web shells observed in this campaign, BUSHWALK is written in Perl and embedded into a legitimate Ivanti Connect Secure component, querymanifest.cgi.

  • web:cybernoz.com

    Feb 01, 2024 NewsroomNetwork Security / Malware Google-owned Mandiant said it identified new malware employed by a China-nexus espionage threat actor known as UNC5221 and other threat groups during post-exploitation activity targeting Ivanti Connect Secure VPN and Policy Secure devices. This includes custom web shells such as BUSHWALK , CHAINLINE, FRAMESTING, and a variant of LIGHTWIRE. "CHAINLINE

  • web:cybersecuritynews.com

    Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.

  • web:malpedia.caad.fkie.fraunhofer.de

    2024-02-27 ⋅ Mandiant ⋅ Ashley Frazer, Ashley Pearson, Austin Larsen, Jacob Thompson, Matt Lin, Robert Wallace, Ryan Gandrud Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts BUSHWALK Kubo Injector PITFUEL PITHOOK PITSOCK

  • web:securityaffairs.com

    The cybersecurity firm reported that threat actors are employing the malware in post-exploitation activity, likely performed through automated methods. Mandiant recently observed a mitigation bypass technique used to deploy a custom web shell tracked as BUSHWALK .

  • web:securityboulevard.com

    Google-owned Mandiant has uncovered a new malware exploiting vulnerabilities in Ivanti Connect Secure VPN and Policy Secure devices. These malwares have been utilized by several threat groups, including the China-nexus espionage group UNC5221, to execute post-exploitation activities. The new malware variants utilized by these threat actors include the custom web shells named BUSHWALK ...

  • web:thehackernews.com

    Google-owned Mandiant said it identified new malware employed by a China-nexus espionage threat actor known as UNC5221 and other threat groups during post-exploitation activity targeting Ivanti Connect Secure VPN and Policy Secure devices. This includes custom web shells such as BUSHWALK , CHAINLINE ...

  • web:undercodenews.com

    🔮 Future Mirai-style malware families will likely incorporate multi-vulnerability exploitation chains targeting Four-Faith routers and similar industrial networking equipment simultaneously.

  • web:www.infocerts.com

    Google-owned Mandiant said it identified new malware employed by a China-nexus espionage threat actor known as UNC5221 and other threat groups during post-exploitation activity targeting Ivanti Connect Secure VPN and Policy Secure devices. This includes custom web shells such as BUSHWALK , CHAINLINE, FRAMESTING, and a variant of LIGHTWIRE.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.