s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-MAL-elf.mumblehard

📛 Threat Title

Malware family: Mumblehard

Category: Mumblehard First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.mumblehard`. Printable name: Mumblehard.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.mumblehard VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.mumblehard

IOC database

Type
domain
Value
elf.mumblehard
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.mumblehard

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.mumblehard

References (1)

Remediations (10)

  • web:github.com

    mumblehard_packer.yar malware -ioc / mumblehard / mumblehard_packer.yar Cannot retrieve latest commit at this time.

  • web:www.breachsense.com

    Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.daemon-security.com

    Mumblehard - Malware that affects Linux and BSD Systems Several websites have discussed this writeup by Marc-Etienne M.Leveille of ESET in regards to the Mumblehard malware ESET discovered while working with a customer.

  • web:www.eset.com

    Linux/ Mumblehard targets servers running Linux and BSD systems. The primary purpose of this malware is to use infected systems for spamming bots.

  • web:www.fortiguard.com

    A trojan is a type of malware that performs activities without the user's knowledge. These activities commonly include establishing remote access connections, capturing keyboard input, collecting system information, downloading/uploading files, dropping other malware into the infected system, performing denial-of-service (DoS) attacks, and running/terminating processes.

  • web:www.ncsc.gov.uk

    This guidance helps private and public sector organisations deal with the effects of malware (which includes ransomware). It provides actions to help organisations prevent a malware infection, and also steps to take if you're already infected. Following this guidance will reduce: the likelihood of becoming infected the spread of malware throughout your organisation the impact of the infection

  • web:www.programmersought.com

    Researchers at ESET have discovered a family of malware whose attack targets are operating systems running Linux and FreeBSD. This kind of malware is called " Mumblehard " ( Mumblehard ), which helps attackers create backdoors to provide control of the attacked system.

  • web:www.securityweek.com

    Researchers at ESET have identified a family of malware targeting web servers running the Linux and FreeBSD operating systems. The malware has been dubbed 'Mumblehard' , and gives attackers a backdoor that allows them to control the systems they compromise. According to ESET, the malware goes ...

  • web:www.spamfighter.com

    ESET, a security vendor, says that a malware family nicknamed Mumblehard has been identified which is apparently infecting Linux and BSD web servers for more than 5 years now.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Reputation of linked indicators

DomScan scores the domains, AbuseIPDB + GreyNoise score the IPs. Verdicts are per-indicator — this is a roll-up, so no lookup is triggered by opening this page.

Domains scored
1 / 1
IPs scored
0 / 0
Flagged
1
IndicatorTypeVerdictScore
elf.mumblehard domain high 44