WEBC2-RAVE

WEBC2-RAVEWEBC2-RAVE

Description

A WEBC2 backdoor is designed to retrieve a Web page from a pre-determined C2 server. It expects the Web page to contain special HTML tags; the backdoor will attempt to interpret the data between the tags as commands. This family of malware will set itself up as a service and connect out to a hardcoded web page and read a modified base64 string from this webpage. The later versions of this malware supports three commands (earlier ones are just downloaders or reverse shells). The first commands will sleep the malware for N number of hours. The second command will download a binary from the encoded HTML comment and execute it on the infected host. The third will spawn an encoded reverse shell to an attacker specified location and port.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
WEBC2-UGX
Software
WEBC2-Y21K
Software
WEBC2-CSON
Software
WEBC2-AUSOV
Software
WEBC2-DIV
Software
WEBC2-GREENCAT
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.