Sustes is a malware label observed in ClamAV detection content as "Txt.Malware.Sustes" and "Txt.Malware.Sustes-6779550-1." In the provided context, it appears in Cisco Talos/ClamAV coverage related to widespread exploitation of Apache Log4j vulnerabilities, primarily CVE-2021-44228 (Log4Shell). The surrounding reporting states that Log4j exploitation enabled unauthenticated remote code execution and was used to deliver multiple follow-on payloads, including cryptocurrency miners, Mirai botnet infections, and activity involving known Cobalt Strike servers. However, the provided content does not supply high-confidence technical details specific to Sustes itself beyond its presence as a ClamAV malware signature name associated with these exploitation campaigns. No specific infection vector, platform targeting, threat actor attribution, industry targeting, or standalone indicators of compromise are directly provided for Sustes beyond the ClamAV signature names.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ClamAV signatures include "Txt.Malware.Sustes" in the list of malware activity associated with ongoing exploitation campaigns.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware referenced via detection signatures as associated with ongoing Log4j exploitation activity; specific functionality not described in the provided content.
Malware family referenced via detection signatures as associated with Log4j exploitation activity; specific functionality not described in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.