Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Here is a list of other vulnerabilities this malware variant tries to exploit: CVE-2021-22991 F5 BIG-IP Buffer Overflow | In particular, we have been closely monitoring the developments of the MANGA variant because it is one of the most active in terms of adding new exploit vectors to its list.
Here is a list of other vulnerabilities this malware variant tries to exploit: CVE-2021-22986 F5 iControl REST Remote Code Execution | In particular, we have been closely monitoring the developments of the MANGA variant because it is one of the most active in terms of adding new exploit vectors to its list.
Here is a list of other vulnerabilities this malware variant tries to exploit: CVE-2021-27561/CVE-2021-27562 Yealink DM (Device Management) Remote Code Execution | In particular, we have been closely monitoring the developments of the MANGA variant because it is one of the most active in terms of adding new exploit vectors to its list.
Here is a list of other vulnerabilities this malware variant tries to exploit: CVE-2020-28188 TerraMaster TOS Remote Code Execution | In particular, we have been closely monitoring the developments of the MANGA variant because it is one of the most active in terms of adding new exploit vectors to its list.
Here is a list of other vulnerabilities this malware variant tries to exploit: CVE-2021-27561/CVE-2021-27562 Yealink DM (Device Management) Remote Code Execution | In particular, we have been closely monitoring the developments of the MANGA variant because it is one of the most active in terms of adding new exploit vectors to its list.
Here is a list of other vulnerabilities this malware variant tries to exploit: CVE-2018-10088 XiongMai uc-httpd Buffer Overflow | In particular, we have been closely monitoring the developments of the MANGA variant because it is one of the most active in terms of adding new exploit vectors to its list.
Here is a list of other vulnerabilities this malware variant tries to exploit: CVE-2021-22502 Micro Focus OBR Remote Code Execution | In particular, we have been closely monitoring the developments of the MANGA variant because it is one of the most active in terms of adding new exploit vectors to its list.
Here is a list of other vulnerabilities this malware variant tries to exploit: CVE-2020-25506 D-Link DNS-320 Remote Code Execution | In particular, we have been closely monitoring the developments of the MANGA variant because it is one of the most active in terms of adding new exploit vectors to its list.
CVE-2021-1498 (Cisco HyperFlex HX Remote Code Execution) Figure 11 Sample request targeting CVE-2021-1498 | In particular, we have been closely monitoring the developments of the MANGA variant because it is one of the most active in terms of adding new exploit vectors to its list.
Here is a list of other vulnerabilities this malware variant tries to exploit: CVE-2020-29557 D-Link DIR-825 Buffer Overflow | In particular, we have been closely monitoring the developments of the MANGA variant because it is one of the most active in terms of adding new exploit vectors to its list.
Here is a list of other vulnerabilities this malware variant tries to exploit: CVE-2009-4490 mini_httpd 1.18 Escape Sequence | In particular, we have been closely monitoring the developments of the MANGA variant because it is one of the most active in terms of adding new exploit vectors to its list.
CVE-2021-31755 (Tenda Router AC11 Remote Code Execution) Figure 12 Sample request targeting CVE-2021-31755 | In particular, we have been closely monitoring the developments of the MANGA variant because it is one of the most active in terms of adding new exploit vectors to its list.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.