s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.kaiji

📛 Threat Title

Malware family: Kaiji

Category: Kaiji First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.kaiji`. Printable name: Kaiji.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.kaiji VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kaiji

IOC database

Type
domain
Value
elf.kaiji
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.kaiji

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kaiji

References (1)

Remediations (10)

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as Kaiji .

  • web:blog.sekoia.io

    This article is the opening chapter of a four-part Advent of Configuration Extraction series. The series outlines the methodology we employ at Sekoia's Threat Detection & Research (TDR) team to automate the extraction of malware configuration data, from initial analysis to the production of usable intelligence. Each post of the series focuses on a different scenario, such as analysing .NET ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Surfaced in late April 2020, Intezer describes Kaiji as a DDoS malware written in Go that spreads through SSH brute force attacks. Recovered function names are an English representation of Chinese words, hinting about the origin. The name Kaiji was given by MalwareMustDie based on strings found in samples.

  • web:thrive.trellix.com

    Exposed Docker containers were targeted with malware capable of performing distributed denial of service attacks or turning the infected system into a botnet. The malicious software captured system details including running processes, CPU information, directories, and network data.

  • web:www.aquasec.com

    For more prevention and remediation strategies, including Aqua's Runtime Protection Policies, visit our Support Portal. Kaiji's Invisible Grip: How Persistence and Deception Keep It Alive Kaiji's authors have invested tremendous effort into staying on machines once they've gained access.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.infosecinstitute.com

    Kaiji also compromises IoT devices. The origin of this malware is China and it is written in the Golang or Go programming language. Kaiji can be prevented by patching security flaws, using IPS and IDS, using robust lightweight cryptography for IoT, utilizing CDN and so on.

  • web:www.securityweek.com

    The botnet, which security researcher MalwareMustDie , is of Chinese origin and spreads exclusively via SSH brute force attacks, targeting the root user only. Designed to launch distributed denial of service (DDoS) attacks, the malware requires root access to craft custom network packets and operate unhindered.

  • web:www.sysdig.com

    Kaiji malware As far as behavioral attributes, we concur with previous reporting that this Chaos malware is an evolution of the Kaiji botnet, with much of the same previously reported functionality. To summarize, Kaiji was a DDoS botnet that mainly attacked IoT devices via SSH brute-forcing, hence the source language being Go and easy cross-compilation to common IoT architectures like PowerPC ...

  • web:www.trendmicro.com

    We detected variants of two Linux botnet malware - XORDDoS and Kaiji - targeting exposed Docker servers. XORDDoS infiltrated the Docker server to infect all containers it hosts, while the Kaiji attack used its own container with its DDoS malware .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.