s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.masol

📛 Threat Title

Malware family: MASOL

Category: MASOL First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.masol`. Printable name: MASOL.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.masol VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.masol

IOC database

Type
domain
Value
elf.masol
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.masol

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.masol

References (1)

Remediations (10)

  • web:apt.etda.or.th

    Last change to this tool card: 28 December 2024 Download this tool card in JSON format All groups using tool MASOL RAT

  • web:cybersecsentinel.com

    Threat Group: Earth Estries (also known as Salt Typhoon, GhostEmperor, UNC2286) Threat Type: Advanced Persistent Threat (APT) Exploited Vulnerabilities: Multiple N-day vulnerabilities in Ivanti Connect Secure, Fortinet FortiClient EMS, Sophos Firewall, and Microsoft Exchange Server Malware Used: GHOSTSPIDER backdoor, MASOL RAT, Demodex rootkit, Deed RAT (SNAPPYBEE) Threat Score: High (8.

  • web:cybersecuritynews.com

    Their activities frequently coincide with the TTPs of other well-known Chinese APT organizations, suggesting that they may be using shared tools from malware -as-a-service vendors. Earth Estries performs stealthy attacks that begin with edge devices and spread to cloud environments, making detection tough.

  • web:dl.acm.org

    In response, Artificial Intelligence (AI) models are increasingly leveraged to enhance malware classification and remediation efforts. However, while such models trained to classify malware datasets often perform well in controlled environments, research increasingly shows that conventional AI-based malware classifiers struggle to generalize to ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the MASOL malware family including references, samples and yara signatures.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.darkreading.com

    Salt Typhoon Builds Out Malware Arsenal With GhostSpider The APT, aka Earth Estries, is one of China's most effective threat actors, performing espionage for sometimes years on end against telcos ...

  • web:www.imda.gov.sg

    Leveraging vulnerabilities in public-facing servers to gain initial access, they employ advanced malware such as GHOSTSPIDER, SNAPPYBEE and MASOL RAT, alongside stealth techniques like living-of-the-land binaries and complex C2 infrastructure.

  • web:www.infosecurity-magazine.com

    Chinese state-sponsored threat actor Earth Estries is deploying new malware tools to target government and telecoms organizations globally, according to an analysis by Trend Micro. This includes two backdoors named GhostSpider and Masol RAT to avoid detection and enable prolonged espionage ...

  • web:www.trendmicro.com

    We observed the new Linux variant of MASOL in the wild after 2021. However, we haven't seen the Windows variant of MASOL after 2021. Currently, we have moderate to high confidence that Earth Estries uses MASOL RAT to target Linux servers within Southeast Asian governments recent years. Figure 13. The extracted MASOL RAT malware configuration ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.