Bring Your Own Command & Control (BYOC2) | Huntress
ID: 9a8484b1-cdd0-5138-8426-7396a45be312
STIX ID: report--9a8484b1-cdd0-5138-8426-7396a45be312
Feed Name: Huntress Blog
Threat Score
Huntress analyzes a JScript/Valak malware sample that bluntly includes plaintext C2 domains and loads additional JavaScript from a registry key; the sample builds Base64-encoded C2 endpoints, polls multiple domains for --TASK payloads, decodes and executes tasks via WMIC and scheduled tasks for persistence and command execution, and the blog post provides IOCs and links to the discovered code.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
