Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
TDSS (a.k.a TDL-4 and Alureon), a stealthy “rootkit” that installs deep within infected PCs and loads even before the underlying Windows operating system boots up.
A file called Socks.dll has been added to TDSS’s svchost.exe; it is used to establish a proxy server on an infected computer.
TDSS uses a public P2P network in order to transmit commands to all infected computers in the botnet.
As before, affiliate programs offer a TDL distribution client that checks the version of the operating system on a victim machine and then downloads TDL-4 to the computer.
The source request is encrypted and then converted to base64. Random strings in base64 are prepended and appended to the received message.
One of the key changes in TDL-4 compared to previous versions is an updated algorithm encrypting the protocol used for communication between infected computers and botnet command and control servers... The source request is encrypted and then converted to base64... the request is sent to the server using HTTPS.
75 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
TDL-4 is described as a bootkit/downloader used to fetch additional malware, including Glupteba.
A kernel-mode rootkit/bootkit for Windows that infects the boot process, supports x64 systems, bypasses driver-signing restrictions, injects C&C payload DLLs into processes, hides components via its own virtual file system, and can download additional payloads.
Named botnet mentioned as a notable example.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.