QUADAGENT
Description
(Palo Alto) Once the QUADAGENT payload has executed, it will use rdppath[.]com as the C2, first via HTTPS, then HTTP, then via DNS tunneling, each being used as a corresponding fallback channel if the former fails.
Names
Name |
---|
QUADAGENT |
Category
Malware
Type
- Backdoor
- Tunneling
Information
Mitre Attack
Malpedia
Alienvault Otx
Other Information
Uuid
0951e35a-f91b-43e8-936a-e6b6f1439555
Last Card Change
2020-04-23