Open Threat Intel Archive
OTIA
Indicators
ATT&CK
Threat actors
MITRE ATT&CK intrusion sets
Malware & tools
Software families & tooling
Techniques
Tactics & techniques
Reports
Sources
Developers
JSON API
Free CORS-enabled endpoints
MCP server
Model Context Protocol access
Source code
This project on GitHub
Loading the archive…
Open Threat Intel Archive
← Malware & tools
S0547
malware
DropBook
DropBook is a Python-based backdoor compiled with PyInstaller.
Platforms
Windows
MITRE ATT&CK ↗
Linked entities · 10
uses
T1059.006
Python
uses
T1059.003
Windows Command Shell
uses
T1083
File and Directory Discovery
uses
T1102
Web Service
uses
T1567
Exfiltration Over Web Service
uses
T1105
Ingress Tool Transfer
uses
T1140
Deobfuscate/Decode Files or Infor…
uses
T1614.001
System Language Discovery
uses
T1082
System Information Discovery
uses by
G0021
Molerats