Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On September 13, 2016 Microsoft released a security bulletin fixing the CVE-2016-3351 vulnerability, which included a patch for Internet Explorer and Edge browsers. Researchers found exploitation dating back to January 2014, including a malvertising chain leading to Angler EK and dropping Reveton.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Figure 6: Another malvertising chain leveraging CVE-2016-3351 in september 2014 leading to Astrum
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The malicious version of the graphic has a script encoded in its alpha channel, which defines the transparency of each pixel.
The payload is then decrypted and launched via regsvr32.exe or rundll32.exe.
It is particularly interested in presence software containing the following strings in their filenames: vmtoolsd.exe VBoxService.exe prl_tools_service.exe VBoxHook.dll SBIEDLL.DLL fiddler.exe charles.exe wireshark.exe...
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.