Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Each version has also used virtualization packers such as VMP, Enigma, etc. to protect itself.
The information collected by v1 version includes: volume serial number (HWID), computer name, user name, operating system name, system version, installed capture driver name, antivirus information, parent process file modification time, top window name and window title, etc.
Orchard uses a redundant C2 mechanism of "hardcoded domain + DGA"... C2 communication process is relatively simple, the bot in the check-in process will contact C2 to send the collected host information, and then wait for C2 response.
The second seed is obtained by making a GET request to the following URL: https://blockchain.info/balance?active=1A1zP1eP5QGefi2DMPTfTL5SLmv7DivfNa
47 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Orchard is a cryptojacking malware/downloader that uses a domain generation algorithm seeded by the current date and the Bitcoin genesis block balance. It uses generated domains and a hardcoded domain to control XMRig mining activity on infected Windows systems.
A multi-version botnet family using DGA plus hardcoded C2 domains, with capabilities including host profiling, command execution, downloading and executing additional payloads, USB-based propagation, and in its latest version deployment of XMRig for Monero cryptomining.
A botnet family using a redundant hardcoded-domain plus DGA C2 scheme. Across at least three versions since 2021-02, it collects host data, receives commands, downloads and executes next-stage payloads, spreads via USB device infection, and in its latest version focuses on Monero mining.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.