logo

Tracking the entire iceberg – long‑term APT malware C2 protocol emulation and scanning

ID: 60db3798-7a58-4899-acf6-6210fb04f074

STIX ID: report--60db3798-7a58-4899-acf6-6210fb04f074

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2022-09-19

Last Modified Date: 2022-09-19

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report documents reverse engineering and protocol emulation for Winnti 4.0 and ShadowPad C2s, the implementation of scanners (ZMap + custom Python/IDA Appcall tooling) to probe multiple protocols/ports (TCP/TLS/HTTP/HTTPS/UDP/DNS), and the Internet-wide discovery of active C2 infrastructure (51 Winnti 4.0 and 72 ShadowPad C2 servers across the tracking periods). It provides detailed packet/header formats, encoding algorithms, scanner workflows, operational notes for large-scale scanning, and a list of IOCs and sample hashes with observed date ranges.