Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

基于http的C2通信 #23

Open
scarletttt opened this issue Feb 9, 2022 · 0 comments
Open

基于http的C2通信 #23

scarletttt opened this issue Feb 9, 2022 · 0 comments

Comments

@scarletttt
Copy link
Owner

scarletttt commented Feb 9, 2022

当恶意软件已经植入到受害主机后,需要对收集到的环境信息、文件等内容发往C2服务器,基于http协议的C2通信,恶意软件可以用来接收指令、回传数据等。

APT-TrickBot:
malware在一开始,为了确认自己所在主机的网络环境,去ping一个公网应用来探测公网是否可达。
malware读取配置文件,其中列举了可以进行数据回传的C2服务器
image
image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant