Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
* AntiVM * Детект песочниц * Детект всех онлайн сервисов автоматического анализа
* Определение установленного АВ ( на всех ОС Windows кроме серверных )
Here is Neutrino calling back home ... POST /modopo/tasks.php HTTP/1.0 Host: nav1111sto.mcdir.ru ... ping=1 ... getcmd=1&uid=D2BDB99374A80FB8&os=Windows+XP+PRO+(x32)&av=Not+installed&nat=yes&version=2.5
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Bot malware observed as a final payload delivered by ThreadKit campaigns (noted in Feb/March 2018 activity).
A multi-purpose bot capable of password theft, DDoS, and loading additional payloads; here it was used to download Pony.
Initial payload used in a spam campaign as a downloader to retrieve Shifu as a second-stage payload.
A multifunction Windows bot advertised on underground forums as an HTTP stress-testing tool but effectively a DDoS bot. The advertised capabilities include HTTP/HTTPS, TCP, UDP, Slowloris and download flooding, plus loader functionality, keylogging, remote shell command execution, file theft including bitcoin wallets, hosts file modification, Windows key theft, USB/archive propagation, AV detection, updates, anti-debugging, anti-VM, sandbox detection, bot protection, and centralized tasking through an admin panel.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.