Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
After an anti-emulation stage, stage 2 decrypts the final malware, using the key 0x5A4C4D4D4C4D... From the memory segment the code has been decrypted to, it is being written back to the .text section.
24 collect client information and configuration ... 26 get logged on users 26 (r) send logged on users
28 get detailed process information 29 (r) failed to get detailed process information
T1082 System Information Discovery Quasar and NETWIRE both RAT having this feature to discover and collect victim machine information.
10 locate and send file with time, attributes and size 12 find file ... 36 locate and send file from log directory with time, attributes and size 38 check if log file exists
D threaded: get file over HTTP and execute ... 2D get file over HTTP and execute
The infection starts with the delivery of a downloader that downloads multiple payloads... Once the attackers achieve initial compromise, the downloader downloads three files... A Pyrome python backdoor is downloaded by this shellcode. This will also download socat and xmrig miner, and finally xmrig miner downloads another RAT named Quasar.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commodity remote access trojan used to control infected systems, steal stored credentials, and perform keylogging.
A feature-rich remote access trojan/backdoor that communicates with a C2 server over TCP/IP, supports persistence, remote shell, file operations, screenshot capture, keylogging, credential theft from browsers/chat/mail clients, SOCKS proxying, and audio recording. The report also notes NetWire C2 traffic uses a proprietary protocol with AES-256-OFB encryption by default.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.