Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2022-22954, a remote code execution (RCE) vulnerability due to server-side template injection in VMware Workspace ONE Access and Identity Manager, is trivial to exploit with a single HTTP request to a vulnerable device.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Certain injected commands result in the download of obfuscated Perl scripts. Deobfuscating these scripts reveals they are versions of the known bot family “Stealth Shellbot” that reaches out to an IRC server to listen for commands to perform.
The attack starts when tddwrt7s.sh downloads the dota3.tar.gz package from a C2 server. The extracted initall.sh script executes, kicking off the infection chain.
SHELLBOT scripts operate as IRC-based backdoors, allowing attackers to remotely control infected machines via predefined commands sent through an IRC channel.
STEALTH SHELLBOT for remote control via IRC C2... SHELLBOT scripts operate as IRC-based backdoors, allowing attackers to remotely control infected machines via predefined commands sent through an IRC channel.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Publicly available IRC-based backdoor scripts used by OUTLAW for command-and-control, arbitrary command execution, payload download/execution, and persistence.
Obfuscated Perl IRC bot/backdoor used by OUTLAW as a secondary remote-control and persistence mechanism. It connects to an attacker-controlled IRC C2 and can execute shell commands, download and execute payloads, manage malware components, and, in older variants, perform DDoS activity.
An IRC-controlled bot family delivered via obfuscated Perl scripts; it can receive commands, execute shell commands, and make HTTP requests to support scanning and exploitation activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.