s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.derusbi

📛 Threat Title

Malware family: Derusbi

Category: Derusbi First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.derusbi`. Printable name: Derusbi.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.derusbi VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.derusbi

IOC database

Type
domain
Value
elf.derusbi
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.derusbi

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.derusbi

References (1)

Remediations (10)

  • web:apps.dtic.mil

    OSINT has linked the Codoso malware and Briba as the same family , and in some cases, con-flated the two with Derusbi [Hardy 2012, Kovacs 2015]. The outcome of this analysis—if the malware families turned out to be the same—would allow us to have a larger starting point for our analysis.

  • web:attack.mitre.org

    Derusbi Derusbi is malware used by multiple Chinese APT groups. [1] [2] Both Windows and Linux variants have been observed. [3]

  • web:cyber-kill-chain.ch

    The Turbo Campaign, Featuring Derusbi for 64-bit Linux. Retrieved March 2, 2016. FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018. Perigaud, F. (2015, December 15). Newcomers in the Derusbi family . Retrieved December 20, 2017.

  • web:github.com

    Repository of YARA rules made by Trellix ATR Team. Contribute to advanced-threat-research/Yara-Rules development by creating an account on GitHub.

  • web:malpedia.caad.fkie.fraunhofer.de

    A DLL backdoor also reported publicly as " Derusbi ", capable of obtaining directory, file, and drive listing; creating a reverse shell; performing screen captures; recording video and audio; listing, terminating, and creating processes; enumerating, starting, and deleting registry keys and values; logging keystrokes, returning usernames and passwords from protected storage; and renaming ...

  • web:misp-galaxy.org

    Derusbi is malware used by multiple Chinese APT groups. (Citation: Novetta-Axiom) (Citation: ThreatConnect Anthem) Both Windows and Linux variants have been observed.

  • web:redteam.y-security.de

    Derusbi is malware used by multiple Chinese APT groups. 34 Both Windows and Linux variants have been observed. 1

  • web:research.splunk.com

    This malware family is frequently used for espionage, data theft, and system compromise, leveraging custom modules tailored to specific targets. Derusbi's ability to remain undetected for extended periods makes it a significant threat, emphasizing the need for robust monitoring and advanced detection mechanisms to mitigate its impact.

  • web:www.microsoft.com

    Technical information Win32/ Derusbi is a multi-component malware family . It uses different trojans to perform the following actions: The downloaded files will differ depending on the instructions from a malicious hacker. Some variants try to pose as a legitimate install by dropping themselves in folder names such as:

  • web:www.virusbulletin.com

    From stealing sensitive information from Mitsubishi Heavy Industries in 2011 to the Anthem data breach revealed in February 2015, the complexity of the Derusbi malware family has been the real driving force behind these espionage campaigns. Upon entering a targeted company through an exploit of a newly discovered vulnerability, a Derusbi sample would be dropped onto the compromised computer ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.