Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In one notable example, the Lemon Duck operators compromised a system that already had xx.bat and a web shell. After establishing persistence on the system in a non-web shell method, the Lemon Duck operators were observed cleaning up other attackers’ presence on the system and mitigating the CVE-2021-26855 (SSRF) vulnerability using a legitimate cleanup script that they hosted on their own malicious server.
Appendix Microsoft Defender for Endpoint detection details Antivirus Microsoft Defender Antivirus detects exploitation behavior with these detections: ... Exploit:ASP/CVE-2021-27065 ... Defending against exploits and post-compromise activities Attackers exploit the on-premises Exchange Server vulnerabilities in combination to bypass authentication and gain the ability to write files and run malicious code.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
test.bat batch file... allowed them to perform a dump of the LSASS process... an additional overlapping activity... was the running of scripts to snapshot Active Directory with ntdsutil
this batch file performs a backup of the Security Account Manager (SAM) database
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware deployed after Exchange Server exploitation. The attackers used a Chopper web shell, dropped xx.bat to dump SAM/registry hives and enable WinRM persistence, then staged shellcode that fetched Cobalt Strike before deploying DoejoCrypt, which encrypted files with a .CRYPT extension and dropped a readme.txt ransom note.
DoejoCrypt [[URL_b3187638_161]] 2021 年 4 月 (V 5.88)
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.