Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
threat actors targeted organizations using CVE-2020-0688, a remote code execution vulnerability in Microsoft Exchange Server... Initial access was likely achieved by exploiting CVE-2020-0688. An attacker possessing valid user credentials can leverage this vulnerability to execute arbitrary code. | TransportClient.dll contains a PDB string ... that is also present in other identified copies of the web shell. Elements in the string led CTU researchers to name this web shell 'SheepTransportShell'.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TransportClient.dll contains a PDB string ... that is also present in other identified copies of the web shell. Elements in the string led CTU researchers to name this web shell 'SheepTransportShell'.
TransportClient.dll contains a PDB string ... that is also present in other identified copies of the web shell. Elements in the string led CTU researchers to name this web shell 'SheepTransportShell'.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
In addition to creating the named pipe, this variant creates a scheduled task called 'Google Updater'.
In addition to creating the named pipe, this variant creates a scheduled task called 'Google Updater'.
Secureworks incident responders identified web shells on multiple hosts in a customer’s environment... This compromise led to the creation of multiple web shells, including simple China Chopper web shells... the attacker re-entered the environment using the same hostname and the same compromised credentials to upload the TransportClient.dll web shell.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.