Command and Control (C2) Servers 101
ID: 9e78e797-cea6-5d8d-84af-62322a57322e
STIX ID: report--9e78e797-cea6-5d8d-84af-62322a57322e
Feed Name: GreyNoise Labs
Threat Score
This report explains C2 infrastructure and provides a concrete example of an active multi-stage campaign that exploits CVE-2024-4577 to download a crypto-miner payload and a vulnerable driver for privilege escalation; it includes observed domains (down.mvip8.ru, yn.mvip8.ru), changing IPs consistent with fast-flux/DNS churn, file artifacts (Taskmgr.exe, WinRing0x64.sys, config.json), and recommends blocking the identified IPs/domains and related artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
