Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
If the process is running with the appropriate privileges, it uses WMI (Windows Management Instrumentation) to query recognized anti-virus software installed on the host.
This script is set to execute as a task each time the computer starts. This is accomplished by creating a scheduled task with a random-looking service name that is set to run as the SYSTEM user at the highest run level.
This script is set to execute as a task each time the computer starts. This is accomplished by creating a scheduled task with a random-looking service name that is set to run as the SYSTEM user at the highest run level.
Like Kovter, it relies heavily on the registry for staging and storage of configuration data while avoiding more traditional on-access endpoint scanning of files on disk. | The data is stored in the pre-existing registry subkey to update the value... The second configuration is stored in the last remaining value in the ZfjrAilGdH registry subkey.
This script is set to execute as a task each time the computer starts. This is accomplished by creating a scheduled task with a random-looking service name that is set to run as the SYSTEM user at the highest run level.
The HTA is heavily obfuscated... While the requested resource features the extension normally associated with PNG images, it is actually malicious Powershell that has been encrypted using RC4.
killall: Terminate all processes initiated by the malware, delete corresponding files ... kill: Find process of specified component, terminate process, and delete the file
Its first task, however, is to install itself to the system in a less suspicious form, namely as an HTML Application (HTA) that will load the malware from the registry.
Once executed, the malware begins with five anti-analysis checks... It also checks for a host CPU with at least two cores, the presence of a debugger, and finally compares system uptime intervals to determine if the sample is running within a sandbox or virtual machine.
The malware checks for unwanted processes and loaded modules by hashing process file names and module names respectively, then comparing each hash against two separate pre-computed lists for each.
Like Kovter, it relies heavily on the registry for staging and storage of configuration data while avoiding more traditional on-access endpoint scanning of files on disk. | The data is stored in the pre-existing registry subkey to update the value... The second configuration is stored in the last remaining value in the ZfjrAilGdH registry subkey.
A process list is gathered and sent to the URL hxxps://uoibppop[.]tk/clean; no response is expected from the server.
These URLs are later contacted with a comprehensive set of sensitive information from the host.
Once executed, the malware begins with five anti-analysis checks... It also checks for a host CPU with at least two cores, the presence of a debugger, and finally compares system uptime intervals to determine if the sample is running within a sandbox or virtual machine.
This new connection uses Socket.IO web sockets to maintain continuous communication between the victim and the server so the server can periodically send commands. | Empty POST requests are sent to each of the URLs in the first configuration's accl key... The second server contain the host address of an advertisement revenue service and the entire HTTP request that should be made to that server.
56 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.