TF-MAL-elf.steelcorgi
📛 Threat Title
Malware family: STEELCORGI
Description
ThreatFox malware family `elf.steelcorgi`. Printable name: STEELCORGI.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.steelcorgi
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.steelcorgi
IOC database
- Type
- domain
- Value
elf.steelcorgi- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.steelcorgi
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.steelcorgi
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:apt.etda.or.th
Last change to this tool card: 05 April 2022 Download this tool card in JSON format All groups using tool STEELCORGI
-
web:cloud.google.com
STEELHOUND, STEELCORGI and Environment Variable Keying UNC2891 often made use of the STEELCORGI in-memory dropper which decrypts its embedded payloads by deriving a ChaCha20 key from the value of an environment variable obtained at runtime.
-
web:fortiguard.fortinet.com
Linux/ SteelCorgi .A!tr is classified as a trojan.A trojan is a type of malware that performs activites without the user's knowledge. These activitie...
-
web:gbhackers.com
As cloud migration accelerates, threat actors are shifting their focus to Linux ELF malware , tailoring proven techniques for cloud environments. The rise of backdoors, wipers, and sophisticated evasion methods such as dynamic linker hijacking and rootkit functionality means defenders must stay ahead with advanced detection and response.
-
web:github.com
Area Malware reports Parent threat Defense Evasion, Discovery, Lateral Movement, Collection, Command and Control, Impact Finding https://yoroi.company/research/opening- steelcorgi -a-sophisticated-apt-swiss-army-knife/ Industry reference a...
-
web:malpedia.caad.fkie.fraunhofer.de
According to FireEye, STEELCORGI is a packer for Linux ELF files that makes use of execution guardrails by sourcing decryption key material from environment variables.
-
web:openhunting.io
(FireEye) STEELCORGI is a packer for Linux ELF programs that uses key material from the executing environment to decrypt the payload. When first starting up, the malware expects to find up to four environment variables that contain numeric values.
-
web:threatintelligence.garden.handsomezebra.com
Description (FireEye) STEELCORGI is a packer for Linux ELF programs that uses key material from the executing environment to decrypt the payload. When first starting up, the malware expects to find up to four environment variables that contain numeric values. The malware uses the environment variable values as a key to decrypt additional data to be executed.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.