FILEMembers
FILE

One 2009 Compile Job Is the Only Real Link in 'Klovbot' Cluster

A shared imphash, rich-header hash, and January 2009 timestamp prove a Hiloti/Mufanom downloader was compiled once and shipped as both an EXE and a DLL. Everything else the 'klovbot' feed label bundles alongside it turns out to be three unrelated, decade-old commodity families with no shared build artifacts.

Sep 21, 2026, 14:31 (UTC+9)Last seenSep 21, 2026Severity72ByCTX TeamIOC55MITRE48RegionsUS

Everything else in this record is décor around one hard fact: two of the five files carried under a shared feed label share not just a detection verdict but an identical import table hash, an identical rich-header fingerprint, and an identical PE compile timestamp of January 14, 2009. That is not coincidence — it is proof that whoever built the Hiloti/Mufanom downloader compiled it once and shipped it out twice, once packaged as a standalone executable and once as a dynamic-link library, both…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence