Researchers found it on an exposed staging server alongside a fake document-signing page, supporting tools, and an operator dashboard. Because its command channel does not rely on one fixed domain, taking down a malicious website may not disconnect infected devices. The attack begins with a ClickFix lure hosted on Cloudflare Workers. The page... Weiterlesen
Intelligence View
AvisLoader Windows Malware Uses Tox C2 to Survive Domain Takedowns and Maintain Access
Researchers found it on an exposed staging server alongside a fake document-signing page, supporting tools, and an operator dashboard. Because its command channel does not rely on one fixed domain, taking down a malicious website may not…
SOC Incident Playbook: Vulnerability Remediation & Verification
title: Detect Exploitation - AvisLoader Windows Malware Uses Tox C2 to Survive Domain Takedowns and Maintain Access
id: 41fba6e0-b9fe-4da2-84fa-860f1a27d103
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
- https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
category: network_connection
product: any
detection:
selection:
CommandLine|contains:
- 'exploit'
condition: selection
falsepositives:
- Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
- attack.initial_access
- attack.t1071rule CTI_Threat_Indicator {
meta:
author = "iShareStuff CTI Automated Detection Engine"
date = "2026-09-24"
description = "YARA Signature for "
strings:
$str = "AvisLoader Windows Malware Use" ascii wide
condition:
any of them
}tsecurity.de Cognitive Threat RAG
Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich AvisLoader Windows Malware Uses Tox C2 t.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.
Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.
- 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
- 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
- 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
SOCIAL SHARE CARD GENERATOR