Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
After the installation routine completes, Aveo will exfiltrate the following victim information to a remote server via HTTP. Unique victim hash IP Address Microsoft Windows version Username ANSI code page identifier
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PIPXのC2関連調査で、同じ登録者メールアドレスで取得されたドメインを使用していた別系統のマルウェアとして言及されている。
Aveo is a remote access trojan/backdoor disguised as a Microsoft Excel document inside a WinRAR self-extracting archive. It drops a decoy document, installs itself for persistence via the Run registry key, exfiltrates victim information over HTTP using RC4 encryption, and accepts commands from a C2 server to execute shell commands, read/write files, list drives, and gather file attributes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.