Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The C&C domain name for status reporting, task retrieval and to get links to other malware downloads... Periodically, it reports to the C&C that it is alive and well, waiting for additional tasks.
On startup, Sathurbot retrieves its C&C with a query to DNS. The response comes as a DNS TXT record.
72 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sathurbot is a backdoor/downloader botnet delivered via torrent-lure executables. It retrieves C2 information via DNS TXT records, can update itself, download and execute additional payloads, crawl the web for CMS sites, brute-force weak WordPress administrator credentials through the XML-RPC wp.getUsersBlogs API, and in some cases act as a BitTorrent seeder using an integrated libtorrent library.
Mentioned only as another malware example using distributed WordPress password attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.