C2_Communication_of_ThreatNeedle.pdf
ID: cef26e2d-ebb5-43ed-9471-239f18cb093f
STIX ID: report--cef26e2d-ebb5-43ed-9471-239f18cb093f
Threat Score
78/100
Uploaded: 2026-08-14
Published Date: 2021-01-27
Last Modified Date: 2021-01-27
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes a remote-access trojan ("Troy") campaign that exploits IIS/WebDAV and ATMFD vulnerabilities (CVE-2017-7269, CVE-2016-7256), deploys ASP webshells, and operates a multi-tier C2 architecture (Proxy, Mid, Manager) to issue commands, collect device information and exfiltrate files; it includes code samples, log excerpts, command tables and diagrams mapping the malware’s communication and operator workflows.
