remote-access-c3
Description
(Trend Micro) The remote-access-c3 backdoor seems to be inspired by Patchwork’s NDiskMonitor because they share some behaviors, strings, and commands. remote-access-c3 is written in C++ using the Standard Template Library (STL) library. When remote-backdoor-c3 is executed, it waits for a certain time, because of its long initial time delay. It later loads and executes all modules saved in the system registry, establishes persistence via Task Scheduler, and starts a beaconing thread.
Names
Name |
---|
remote-access-c3 |
Category
Malware
Type
- Backdoor
- Info stealer
Information
- https://documents.trendmicro.com/assets/research-deciphering-confucius-cyberespionage-operations.pdf
Other Information
Uuid
ee3e6bbf-bb27-4e85-a430-a09a76acab17
Last Card Change
2020-04-20