Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Recently, FortiGuard Labs came across several malicious documents that exploit the vulnerability CVE-2012-0158... Solution: To prevent triggering this RTF exploit, it is important to apply the patches released by Microsoft that cover CVE-2012-0158 vulnerability.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
This is because the ‘MZ’ in the IMAGE_DOS_HEADER, the DOS stub, and the ‘PE’ signature were deliberately removed. This was done to prevent the dumped file from being analyzed properly in a debugger and decompiler.
taskeng.exe and SC&Cfg.exe are signed legitimate applications; however, they are tricked into loading malware that are disguised as the legitimate Goopdate.dll and Vsodscpl.dll files.
As an anti-VM, it checks whether the environment has the registry key: HKCR\Applications\VMwareHostOpen.exe
Before it can download the NewCore RAT, it needs to send the following information to the C&C server: OS version Processor speed Number of processors Physical memory size Computer name User name User privilege Computer IP address Volume serial number
The response is an XOR encrypted data that includes the encrypted NewCore RAT.
The above information is converted to its hex string representation, and then sent to the C&C server via HTTP GET
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan used by Temp.Conimes in attacks against Vietnamese organizations.
Remote access trojan used post-compromise; variants (BlueCore/RedCore) used in Southeast Asia, with additional tooling downloaded for persistence and credential/cookie theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.