Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Malware

Eimeria

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

12 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

3 techniques
T1053.005Scheduled TaskEvidence2

Scheduled task Material_ReportFootballHost_Startup

T1059Command and Scripting InterpreterEvidence1

Deal.exe is the AutoIt-compiled RunPE loader. Compiled with AutoIt3, it embeds both the AutoIt runtime and a 24,773-line compiled pcode script.

T1574.001DLLEvidence1

The attack vector is DLL side-loading. Both files sit together in jjez/ . When dsclock.exe runs, Windows loads zlibwapi.dll from the same directory before checking system paths.

Persistence

2 techniques
T1053.005Scheduled TaskEvidence2

Scheduled task Material_ReportFootballHost_Startup

T1547.001Registry Run Keys / Startup FolderEvidence2

Run key HKCU\...\Run\ReportFootballHost_EXX

Privilege Escalation

3 techniques
T1053.005Scheduled TaskEvidence2

Scheduled task Material_ReportFootballHost_Startup

T1055.012Process HollowingEvidence2

The recovered Deal.exe layer is an AutoIt RunPE loader with process hollowing imports.

T1547.001Registry Run Keys / Startup FolderEvidence2

Run key HKCU\...\Run\ReportFootballHost_EXX

Stealth

5 techniques
T1055.012Process HollowingEvidence2

The recovered Deal.exe layer is an AutoIt RunPE loader with process hollowing imports.

T1140Deobfuscate/Decode Files or InformationEvidence2

msbuilder64.dll encrypted blob ... Decrypted IExpress layer ... RC4 key wNDRKtWS12MEvmD4jr3ZyvqQTviBYboE5Ce Compression LZNT1 via RtlDecompressBuffer

T1497.001System ChecksEvidence1

Anti-analysis ... Pi calculation ... checks sqrt(sum*6) > 3.1415 . Fails under emulation. Sleep check Compares real vs emulated sleep duration Stress test CPU/memory stress test to detect thin VPS

T1564.001Hidden Files and DirectoriesEvidence1

Directory AppData\Local\Material\ReportFootballHost (hidden + system attributes)

T1574.001DLLEvidence1

The attack vector is DLL side-loading. Both files sit together in jjez/ . When dsclock.exe runs, Windows loads zlibwapi.dll from the same directory before checking system paths.

Discovery

1 technique
T1497.001System ChecksEvidence1

Anti-analysis ... Pi calculation ... checks sqrt(sum*6) > 3.1415 . Fails under emulation. Sleep check Compares real vs emulated sleep duration Stress test CPU/memory stress test to detect thin VPS

Collection

1 technique
T1560Archive Collected DataEvidence1

Decryption ... reveals a PE32+ executable ... Capa identifies it as an IExpress self-extracting archive ... The embedded CAB file sits at IExpress stub offset 0x2a830.

Command and Control

2 techniques
T1071Application Layer ProtocolEvidence1

The final injected payload is an 8,355-byte PE ... a .NET assembly that connects to ws://94.26.90.139:3006 ... Transport TCP, WebSocket

T1071.001Web ProtocolsEvidence1

IP:Port 94.26.90[.]139:3006 Extracted WebSocket C2 endpoint

Other

1 technique
T1562.001Disable or Modify ToolsEvidence1

Restore ntdll -- loads a clean copy of ntdll.dll from the filesystem, overwriting userland EDR hooks before any injection runs.

INDICATORS OF COMPROMISE

IOCs tracked for this family

8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
6 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
1 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
hash.sha256●●●●●●●●●●●●View more in app1 month ago
hash.sha256●●●●●●●●●●●●View more in app1 month ago
hash.sha256●●●●●●●●●●●●View more in app1 month ago
hash.sha256●●●●●●●●●●●●View more in app1 month ago
hash.sha256●●●●●●●●●●●●View more in app1 month ago
hash.sha256●●●●●●●●●●●●View more in app1 month ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching8

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping12

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.