s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-php.dewmode

📛 Threat Title

Malware family: DEWMODE

Category: DEWMODE First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `php.dewmode`. Printable name: DEWMODE.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain php.dewmode VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/php.dewmode

IOC database

Type
domain
Value
php.dewmode
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-php.dewmode

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/php.dewmode

References (1)

Remediations (9)

  • web:assets.recordedfuture.com

    The compromise of the Accellion File Transfer Appliance (FTA) file sharing service impacting nearly 100 clients of the company was enabled primarily by 4 zero-day vulnerabilities in the tool that allowed threat actors to place the DEWMODE web shell on victim servers and exfiltrate files from those servers.

  • web:cloud.google.com

    Threat actors exploit multiple zero-day vulnerabilities in Accellion's legacy File Transfer Appliance to install a newly discovered web shell named DEWMODE .

  • web:community.f5.com

    This page is used to install a simple eval WebShell, which is then used to upload the more sophisticated DEWMODE WebShell. Mitigation with Advanced WAF Advanced WAF customers under any supported version are already protected against this vulnerability as exploitation attempts will be detected by SQL Injection and Command Execution attack ...

  • web:detection.fyi

    Detects access to DEWMODE webshell as described in FIREEYE report

  • web:icsstrive.com

    Multiple Accellion FTA customers suffered attacks from UNC2546 and have received extortion emails threatening to publish stolen data on the "CL0P^_- LEAKS" .onion website. Some of the published victim data appears to have been stolen using the DEWMODE web shell.

  • web:industrialcyber.co

    Beyond CL0P ransomware, TA505 is known for frequently changing malware and driving global trends in criminal malware distribution." According to the advisory, in a campaign from 2020 to 2021, TA505 used several zero-day exploits to install a web shell named DEWMODE on internet-facing Accellion FTA servers.

  • web:malpedia.caad.fkie.fraunhofer.de

    FireEye discovered the DEWMODE webshell starting mid-December 2020 after exploitation of zero-day vulnerabilities in Accellion's File Transfer Appliance. It is a PHP webshell that allows threat actors to view and download files in the victim machine. It also contains cleanup function to remove itself and clean the Apache log.

  • web:www.bleepingcomputer.com

    The intruders stole the data via DEWMODE but did not encrypt the compromised systems. In late January, though, victims started to get extortion emails from someone threatening to publish the ...

  • web:www.trendmicro.com

    This Backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. It may arrive using one or multiple arrival methods.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.