Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Worm:Win32/Morto.A connects to the following hosts in order to download additional information and update its components: 210.3.38.82 74.125.71.104 jifr.info jifr.co.cc jifr.co.be qfsl.net qfsl.co.cc qfsl.co.be
37 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as malware leveraging DNS for command-and-control communications.
A Windows worm that spreads over local networks, contacts remote hosts to download additional components and updates, uses generated temporary executable filenames, and can be instructed to perform denial-of-service attacks against specified targets.
A Windows worm that brute-forces weak RDP credentials across local subnets, installs a malicious DLL (clb.dll), gains unauthorized access, downloads additional components, can perform denial-of-service attacks, terminates security-related processes, and clears system event logs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.