logo

C2_Communication_of_ThreatNeedle.pdf

ID: cef26e2d-ebb5-43ed-9471-239f18cb093f

STIX ID: report--cef26e2d-ebb5-43ed-9471-239f18cb093f

Threat Score

78/100

Uploaded: 2026-08-14

Published Date: 2021-01-27

Last Modified Date: 2021-01-27

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes a remote-access trojan ("Troy") campaign that exploits IIS/WebDAV and ATMFD vulnerabilities (CVE-2017-7269, CVE-2016-7256), deploys ASP webshells, and operates a multi-tier C2 architecture (Proxy, Mid, Manager) to issue commands, collect device information and exfiltrate files; it includes code samples, log excerpts, command tables and diagrams mapping the malware’s communication and operator workflows.