TSCOOKIERAT
TSCOOKIERATTSCookieRAT
Description
TSCookie provides parameters such as C&C server information when loading TSCookieRAT. Upon the execution, information of the infected host is sent with HTTP POST request to an external server. (The HTTP header format is the same as TSCookie.)
The data is RC4-encrypted from the beginning to 0x14 (the key is Date header value), which is followed by the information of the infected host (host name, user name, OS version, etc.). Please refer to Appendix C, Table C-1 for the data format.
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.