remote-access-c3

Description

(Trend Micro) The remote-access-c3 backdoor seems to be inspired by Patchwork’s NDiskMonitor because they share some behaviors, strings, and commands. remote-access-c3 is written in C++ using the Standard Template Library (STL) library. When remote-backdoor-c3 is executed, it waits for a certain time, because of its long initial time delay. It later loads and executes all modules saved in the system registry, establishes persistence via Task Scheduler, and starts a beaconing thread.

Names

Name
remote-access-c3

Category

Malware

Type

  • Backdoor
  • Info stealer

Information

Other Information

Uuid

ee3e6bbf-bb27-4e85-a430-a09a76acab17

Last Card Change

2020-04-20