s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-php.dollyway

📛 Threat Title

Malware family: DollyWay

Category: DollyWay First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `php.dollyway`. Printable name: DollyWay.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain php.dollyway VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/php.dollyway

IOC database

Type
domain
Value
php.dollyway
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-php.dollyway

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/php.dollyway

References (1)

Remediations (10)

  • web:cyberpress.org

    A massive malware campaign dubbed " DollyWay World Domination" that has compromised over 20,000 WordPress websites.

  • web:cybersecuritynews.com

    This operation is notable for its advanced techniques in maintaining control over infected sites and its sophisticated methods of injecting malware . The DollyWay malware primarily targets WordPress sites, leveraging a network of compromised sites to redirect visitors to scam pages through traffic broker networks.

  • web:dailysecurityreview.com

    The DollyWay malware campaign has compromised 20,000+ WordPress sites. Learn about its multi-stage attack, persistence, and evasion techniques. Protect your WordPress site now!

  • web:en.softonic.com

    A persistent malware campaign known as DollyWay has compromised over 20,000 WordPress websites worldwide, redirecting users to fraudulent gambling, crypto, and sweepstakes sites. Security researchers at GoDaddy have been tracking this threat, which has evolved over the years to improve its evasion tactics and reinfection strategies. Given its ability to bypass security measures and repeatedly ...

  • web:protectyourwp.com

    The latest campaign ( DollyWay ) demonstrates sophisticated capabilities including cryptographically signed data transfers, heterogeneous injection methods, and automatic reinfection mechanisms. Threat actors attempt to maintain control of compromised sites by removing any competing malware and updating WordPress.

  • web:www.bleepingcomputer.com

    A malware operation dubbed 'DollyWay' has been underway since 2016, compromising over 20,000 WordPress sites globally to redirect users to malicious sites.

  • web:www.godaddy.com

    Key findings GoDaddy Security researchers have uncovered a long-running malware operation dating back to 2016 that has compromised over 20,000 websites globally in the past 8 years. Campaign infrastructure currently leverages a distributed network of compromised WordPress sites as TDS and Command and Control (C2) nodes. The latest campaign ( DollyWay ) demonstrates sophisticated capabilities ...

  • web:www.linkedin.com

    The Evolution of a Persistent Threat: DollyWay Malware Campaign Our GoDaddy InfoSec team has connected multiple malware campaigns into a single, long-running operation we've named " DollyWay World ...

  • web:www.scworld.com

    Moreover, DollyWay ensures persistence by automating site reinfection following page loads, according to researcher Denis Sinegubko, who also noted that the campaign's obfuscation of installed WPCode and admin users further complicates its removal from impacted websites.

  • web:www.techradar.com

    A single threat actor DollyWay is currently in its third iteration, while the previous ones were more focused on malware distribution and phishing.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.