Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
As a stealth technique, when a read is directed at cylinder 0, sector 1, head 0, the virus returns the original boot sector to the requesting program instead of the viral code, effectively spoofing many antivirus and disk utilities. | Upon execution, the virus intercepts the interrupt vector table by redirecting INT D3h ... to INT 13h. Once resident, AntiEXE loads a replacement INT 13h handler to monitor disk activity.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A boot sector virus that infects the master boot record of hard drives and the boot sectors of floppy disks. It becomes memory-resident during boot, hooks disk interrupts for stealth and propagation, and carries a payload that corrupts the header of a specific unidentified .exe file.
Boot-record virus noted for consuming 1KB of conventional memory.
A named virus noted for reducing available conventional memory by 1KB.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.