Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
As the script executes it first adds one of three startup methods which will execute the script on Windows startup: ... Startup task ( not implemented yet )
The script drops two other samples on the file system: C:\Windows\System32\wscript.exe" //B "C:\Users\admin\AppData\Roaming\HUAqCSmCDP.js C:\Windows\System32\wscript.exe" "C:\Users\admin\AppData\Local\Temp\hworm.vbs
When executed each SFX file opens a decoy document, video, or URL, and eventually executes an Hworm payload in the background.
The other two files found along with this PDF at its arrival via phishing email have the exact same content (even same hash) in spite of having a different name: LIST OF AVAILABLE JOBS.js SALARY AND HIRING CONDITIONS.js This highly obfuscated JavaScript has the only purpose of dropping a second VBS script
As the script executes it first adds one of three startup methods which will execute the script on Windows startup: ... Startup task ( not implemented yet )
This highly obfuscated JavaScript has the only purpose of dropping a second VBS script... After deobfuscating the VBS script we could identify the malware sample as Houdini’s H-Worm , but preceded by an interesting line, still slightly obfuscated.
The original filenames of these delivery files are related to political figures and groups in the Middle East and the Mediterranean.
Using CallWindowProcW the script will jump to the RunPE shellcode and the shellcode will inject the file (FILE_DATA) into the host process.
It will then register DynamicWrapperX: regsvr32 . exe / I / S < filename_dynamic_wrapperx >
It includes the string “new_houdini”, the mutex used by the implant, the name of the user, the operating system version, the version of the implant, and the name of the foreground process
It includes the string “new_houdini”, the mutex used by the implant, the name of the user, the operating system version, the version of the implant, and the name of the foreground process
Misc : Provides the ability to list processes or modules and kill running processes
It includes the string “new_houdini”, the mutex used by the implant, the name of the user, the operating system version, the version of the implant, and the name of the foreground process
This new version of Hworm uses a mixed binary and ASCII protocol over TCP.
rule wsh_rat_reverse_proxy { ... description = " Alerts on the WSH RAT .NET reverse proxy module " ... $ str_2 = " WSH Reverse Proxy " ... }
89 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A long-running Visual Basic Script-based remote access trojan delivered via phishing emails containing a ZIP archive with an obfuscated JavaScript dropper. The script drops VBS/JS payloads, executes them with wscript.exe, connects to a C2 server, and establishes persistence via both the Run registry key and the Startup folder.
Malware family detected in targeted/APT activity in Southeast Asia during the reporting period.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.