Filler is a historical DOS boot-sector virus referenced in the Virus-L/comp.virus FAQ. The provided content does not describe its internal functionality, payload, or specific infection mechanics beyond indicating that it is detected as a boot-virus-class infection and is commonly discussed alongside Israeli Boot. A notable high-confidence detail is that some antivirus products historically produced false positives for Filler in memory: after a user performed operations such as DIR on an infected floppy, certain scanners could report Filler or Israeli Boot in memory even though the system was not actually infected. The FAQ specifically attributes some of these false positives to another antivirus product, often its TSR scanner/monitor VSAFE, leaving scan strings in memory in unencoded form, which other scanners then misidentified as Filler or Israeli Boot. No additional high-confidence information about threat actor attribution, targeted industries, or concrete indicators of compromise is provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Virus name referenced in the context of antivirus false positives in memory scans.
Virus name referenced in the context of antivirus false positives caused by scanner signatures left in memory.
A named boot-related virus referenced in memory-detection troubleshooting.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.