build_downer is a Windows malware component associated with staged payload delivery and installation. It can download files from command-and-control infrastructure, extract malware concealed within a JPEG image, and execute malware on a compromised host through the WinExec API. The malware includes execution-gating logic based on local system time, using host activity hours to decide when installation should occur. It also performs security software discovery by checking whether antivirus processes are running on the infected system, indicating basic anti-analysis or defense-evasion behavior. For persistence, build_downer adds itself to the Windows Registry Run key and has been observed masquerading under a legitimate-looking value name to reduce suspicion. Overall, the observed behavior is consistent with a downloader used to retrieve, unpack, install, and persist follow-on malware on Windows systems while attempting to avoid detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
Examples include: "Babuk can enumerate disk volumes," "Confucius has used a file stealer that can examine system drives," and "XAgentOSX contains the getInstalledAPP function to run ls -la /Applications to gather what applications are installed."
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that persists by adding itself to a Registry Run key.
Malware that uses WinExec to execute payloads on a compromised host.
Downloader malware that checks local time to time installation activity when the infected system is active.
Downloader malware capable of persisting via a Registry Run key.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.