s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.xmrig

📛 Threat Title

Malware family: XMRIG

Category: XMRIG First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.xmrig`. Printable name: XMRIG.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.xmrig VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.xmrig

IOC database

Type
domain
Value
elf.xmrig
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.xmrig

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.xmrig

References (1)

Remediations (10)

  • web:bazaar.abuse.ch

    Malware samples associated with tag Family.XMRIG MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with Family.XMRIG . Database ...

  • web:blog.gdatasoftware.com

    A team of Security Analysts discovered and examined a resurgence of malware deploying XMRig cryptominer in mid-April this year after a two-year hiatus.

  • web:cloudsecurityalliance.org

    Uptycs uncovered an ongoing operation within the Log4j campaign that aims to deploy an XMRig cryptominer malware onto the targeted systems.

  • web:github.com

    XMRig Incident Response Analysis Overview This project documents the detection, investigation, and remediation of a cryptomining malware incident involving XMRig on a Windows Server 2019 system.

  • web:securityboulevard.com

    Security researchers last year wrote about a surge in the use by threat actors of the legitimate XMRig cryptominer, and cybersecurity firm Expel is now outlining the widening number of malicious ways they're deploying the open-source tool against corporate IT operations.

  • web:steamcommunity.com

    XMRig itself is legitimate open-source software, but if it's installed without your consent, treat it as malware . This guide shows how to stop it, delete the dropped files, and remove the persistence so it can't come back. What you'll do Kill the miner process and jump to its folder Delete the drop directory: C:\\Windows\\SystemHealth\\Update Remove scheduled tasks that re-spawn it ...

  • web:www.checkpoint.com

    XMRig is commonly distributed as a fake update to Adobe Flash Player — which was officially deprecated in 2020 — and may also be bundled with other unwanted applications distributed via fake ads or software downloads. XMRig is well-known cryptomining software, and most anti- malware solutions are capable of recognizing it.

  • web:www.fortra.com

    Executive SummaryThe Fortra Intelligence and Research (FIRE) team has discovered and aided in the mitigation of a malware campaign delivering an open-source cryptocurrency miner, known as XMRig . This campaign stands out to security researchers because cryptojacking or malicious cryptocurrency mining operations rarely target enterprise environments with these methods, and more frequently focus ...

  • web:www.nopalcyber.com

    The XMRig malware campaign demonstrates a high level of operational stealth. By disabling updates, blocking AV scans, and maintaining long-term persistence, it turns infected endpoints into silent crypto-miners.

  • web:www.pcrisk.com

    The games were functional and no malicious activity occurred until December, then a multi-stage infection chain was triggered, with the final payload being XMRIG . Instant automatic malware removal: Manual threat removal might be a lengthy and complicated process that requires advanced IT skills.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.