LONGRUN

LONGRUNLONGRUN

Description

LONGRUN is a backdoor designed to communicate with a hard-coded IP address and provide the attackers with a custom interactive shell. It supports file uploads and downloads, and executing arbitrary commands on the compromised machine. When LONGRUN executes, it first loads configuration data stored as an obfuscated string inside the PE resource section. The distinctive string thequickbrownfxjmpsvalzydg is used as part of the input to the decoding algorithm. When the configuration data string is decoded it is parsed and treated as an IP and port number. The malware then connects to the host and begins interacting with it over a custom protocol.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
Longhorn
Software
BUGJUICE
Software
LongTermMemoryLoss
Software
SNUGRIDE
Software
Runsomewere
Software
WEBC2-GREENCAT
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.