logo

Command and Control (C2) Servers 101

ID: 9e78e797-cea6-5d8d-84af-62322a57322e

STIX ID: report--9e78e797-cea6-5d8d-84af-62322a57322e

Feed Name: GreyNoise Labs

Threat Score
70/100

Date Published: 2024-07-18

Date Updated: 2026-04-27

Author: Konstantin Lazarev

...
...

This report explains C2 infrastructure and provides a concrete example of an active multi-stage campaign that exploits CVE-2024-4577 to download a crypto-miner payload and a vulnerable driver for privilege escalation; it includes observed domains (down.mvip8.ru, yn.mvip8.ru), changing IPs consistent with fast-flux/DNS churn, file artifacts (Taskmgr.exe, WinRing0x64.sys, config.json), and recommends blocking the identified IPs/domains and related artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.