TF-MAL-elf.1337_gtwk_rootkit
📛 Threat Title
Malware family: 1337_GTWK
Description
ThreatFox malware family `elf.1337_gtwk_rootkit`. Printable name: 1337_GTWK.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:docs.sophos.com
Malicious behavior types Aug 19, 2024 This page explains the names we use for malicious behavior detected on computers or servers.
-
web:krebsonsecurity.com
1337 Services Gmbh AS210558 Constella Intelligence Cracked domaintools DreamDrive GmbH Finn Alexander Grimpe finn@shoppy.gg finndev floriaN Florian Marzahl HRB 164175 Intel 471 Lucas Sohn ...
-
web:learn.microsoft.com
Remediation actions can include removing a file, sending it to quarantine, or allowing it to remain. This article includes information and links to resources about specifying what actions should be taken when threats are detected on devices. You can choose from several methods, such as: Configure remediation for Microsoft Defender Antivirus ...
-
web:learn.microsoft.com
Find Microsoft's detection name for a malware family in Defender for Endpoint. Learn how Microsoft malware naming works and how to look up the corresponding detection name.
-
web:malpedia.caad.fkie.fraunhofer.de
elf.1337_gtwk_rootkit (Back to overview) 1337_GTWK Propose Change This is a Linux malware program consisting of several modules, parts of which were likely programmed using AI. It consists of a rootkit and an agent capable of executing malicious code.
-
web:malpedia.caad.fkie.fraunhofer.de
This page gives an overview of all malware families that are covered on Malpedia, supplemented with some basic information for each family .
-
web:plnsgr.github.io
Executive Summary This program performs a malicious operation on the computer by encrypting various file types, rendering them inaccessible to the user. It specifically targets files with certain extensions like documents, images, and more. To ensure persistence, it places copies of itself in startup locations, so it re-executes every time the system boots up. The encrypted files will be ...
-
web:www.huntress.com
Stuxnet removal instructions Manually removing Stuxnet requires isolating the infected systems and using network monitoring tools to identify compromised devices. Regular EDR solutions may help contain threats, while tools like Huntress' remediation services ensure thorough detection, mitigation , and system recovery.
-
web:www.pcrisk.com
What kind of malware is 1337? Our research team found 1337 ransomware during a routine inspection of new submissions to VirusTotal. Malware within this classification is designed to encrypt files in order to make ransom demands for their decryption. On our test machine, 1337 ransomware encrypted files and appended their filenames with a ".1337 " extension. To elaborate, a file initially titled ...
-
web:www.reddit.com
One thing is displaying ads, another thing is automatically downloading software (aka: Malware ) without my permission and that's exactly what the malicious website was trying to do. In the Kaspersky report, it says "Download denied", the malicious website was trying to download something.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.