TF-MAL-php.dewmode
📛 Threat Title
Malware family: DEWMODE
Description
ThreatFox malware family `php.dewmode`. Printable name: DEWMODE.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
php.dewmode
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/php.dewmode
IOC database
- Type
- domain
- Value
php.dewmode- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-php.dewmode
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/php.dewmode
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (9)
-
web:assets.recordedfuture.com
The compromise of the Accellion File Transfer Appliance (FTA) file sharing service impacting nearly 100 clients of the company was enabled primarily by 4 zero-day vulnerabilities in the tool that allowed threat actors to place the DEWMODE web shell on victim servers and exfiltrate files from those servers.
-
web:cloud.google.com
Threat actors exploit multiple zero-day vulnerabilities in Accellion's legacy File Transfer Appliance to install a newly discovered web shell named DEWMODE .
-
web:community.f5.com
This page is used to install a simple eval WebShell, which is then used to upload the more sophisticated DEWMODE WebShell. Mitigation with Advanced WAF Advanced WAF customers under any supported version are already protected against this vulnerability as exploitation attempts will be detected by SQL Injection and Command Execution attack ...
-
web:detection.fyi
Detects access to DEWMODE webshell as described in FIREEYE report
-
web:icsstrive.com
Multiple Accellion FTA customers suffered attacks from UNC2546 and have received extortion emails threatening to publish stolen data on the "CL0P^_- LEAKS" .onion website. Some of the published victim data appears to have been stolen using the DEWMODE web shell.
-
web:industrialcyber.co
Beyond CL0P ransomware, TA505 is known for frequently changing malware and driving global trends in criminal malware distribution." According to the advisory, in a campaign from 2020 to 2021, TA505 used several zero-day exploits to install a web shell named DEWMODE on internet-facing Accellion FTA servers.
-
web:malpedia.caad.fkie.fraunhofer.de
FireEye discovered the DEWMODE webshell starting mid-December 2020 after exploitation of zero-day vulnerabilities in Accellion's File Transfer Appliance. It is a PHP webshell that allows threat actors to view and download files in the victim machine. It also contains cleanup function to remove itself and clean the Apache log.
-
web:www.bleepingcomputer.com
The intruders stole the data via DEWMODE but did not encrypt the compromised systems. In late January, though, victims started to get extortion emails from someone threatening to publish the ...
-
web:www.trendmicro.com
This Backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. It may arrive using one or multiple arrival methods.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.