Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Variant A (callsdk.online) Variant B (weekly-up.online) ... VT score 21/62 – Trojan.NukeSped 27/62 – Trojan.SLoad
17 distinct techniques documented for this family, organized by ATT&CK tactic.
the script executes PowerShell commands and assigns a base64-encoded string to a variable named codigo
The downloaded VBScript ( GB.vbs ) is heavily obfuscated. It employs numerous techniques to obscure its function, such as random variable names and multiple layers of code designed to make analysis difficult.
Using CyberChef, we decode the base64 string to reveal the next stage of the code. The second section extracts a base64-encoded string from within these images.
VirusTotal reports indicate that this .lnk file is packed with malicious PowerShell code, which can identify debugging environments... TimeSerial() function introduces a delay in code execution, potentially bypassing detection by sandbox environments and automated analysis tools.
It even examines the DNS cache for specific domains, such as banking sites, to prepare for targeted attacks.
It performs extensive reconnaissance on the compromised system, including gathering information on running processes
It performs extensive reconnaissance on the compromised system, including gathering information on running processes, identifying Outlook and Citrix files, and capturing screenshots.
It performs extensive reconnaissance on the compromised system, including gathering information on running processes, identifying Outlook and Citrix files
VirusTotal reports indicate that this .lnk file is packed with malicious PowerShell code, which can identify debugging environments... TimeSerial() function introduces a delay in code execution, potentially bypassing detection by sandbox environments and automated analysis tools.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A VBScript implant listed among the indicators of compromise as part of the malware set used in the campaign.
A VBScript implant/load-capable malware classification associated here with the Windows infection chain. It is described as part of a C2-enabled implant that performs Telegram-session checks, browser extension enumeration, and possible next-stage payload delivery.
VirusTotal classified one recovered Windows VBScript implant variant and one PowerShell loader variant as Trojan.SLoad. In this report it appears as an AV classification for campaign payload variants rather than the primary malware family under analysis.
PowerShell-based downloader that performs reconnaissance on infected systems, including collecting running process information, identifying Outlook and Citrix files, capturing screenshots, checking DNS cache for banking-related domains, and downloading/executing additional binaries. It is primarily used to deliver Ramnit.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.