Sisron is a Windows malware family associated with a botnet used for financial fraud and identity theft. It was detected by multiple vendors under names including TOMB, Win32/Agent.WRQ, and Trojan.Scar, and was disrupted by Microsoft during anti-botnet operation B106. Observed activity began in 2013, was most prominent during the summer and fall of that year, declined through 2014, and largely disappeared after takedown actions.
A notable characteristic of Sisron is its deterministic, time-dependent domain generation algorithm. The malware derives candidate command-and-control domains from the current date, applies a modified Base64-style encoding to produce the second-level domain, and rotates across four top-level domains. It backdates the date across a 10-day sliding window, yielding 40 possible domains at a time, and repeatedly cycles through them until one resolves, pausing briefly after failed DNS lookups. This behavior supported resilient command-and-control for the botnet.
Available reporting ties Sisron to financial fraud and identity-theft operations, but the supplied facts do not support a more specific malware classification such as banker or infostealer with high confidence. High-confidence platform evidence indicates it targets Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sisron is malware associated with a botnet used for financial fraud and identity theft. The write-up focuses on its domain generation algorithm (DGA), which generates daily domains from the current date using a modified base64 scheme, cycling across .com, .org, .net, and .info TLDs with a 10-day sliding window for command-and-control resolution.
Mentioned only in AV detection labels within sample listings, not analyzed as a malware subject in this reference.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.