Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. We’ve stumbled across an unknown malware C2 protocol.

We’ve stumbled across an unknown malware C2 protocol.

Scheduled Pinned Locked Moved Uncategorized
7 Posts 1 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • netresec@infosec.exchangeN This user is from outside of this forum
    netresec@infosec.exchangeN This user is from outside of this forum
    netresec@infosec.exchange
    wrote last edited by
    #1

    We’ve stumbled across an unknown malware C2 protocol. Do you know what this is?
    👾 47.83.173.19:5050
    👾 47.84.203.73:5050
    👾 xuanwcai[.]com:5050
    👾 wkaiuahaaxx[.]icu:5050

    Characteristic strings in C2 traffic:
    Accept: */*
    frAQBc8Wsa1xVPfvJcrgRYwTiizs2tr

    Link Preview Image
    netresec@infosec.exchangeN 1 Reply Last reply
    0
    • netresec@infosec.exchangeN netresec@infosec.exchange

      We’ve stumbled across an unknown malware C2 protocol. Do you know what this is?
      👾 47.83.173.19:5050
      👾 47.84.203.73:5050
      👾 xuanwcai[.]com:5050
      👾 wkaiuahaaxx[.]icu:5050

      Characteristic strings in C2 traffic:
      Accept: */*
      frAQBc8Wsa1xVPfvJcrgRYwTiizs2tr

      Link Preview Image
      netresec@infosec.exchangeN This user is from outside of this forum
      netresec@infosec.exchangeN This user is from outside of this forum
      netresec@infosec.exchange
      wrote last edited by
      #2

      This sample is classified as FatalRAT on JoeSandbox, but the C2 traffic doesn't look like FatalRAT
      https://www.joesandbox.com/analysis/1865230/0/html

      netresec@infosec.exchangeN 1 Reply Last reply
      0
      • netresec@infosec.exchangeN netresec@infosec.exchange

        This sample is classified as FatalRAT on JoeSandbox, but the C2 traffic doesn't look like FatalRAT
        https://www.joesandbox.com/analysis/1865230/0/html

        netresec@infosec.exchangeN This user is from outside of this forum
        netresec@infosec.exchangeN This user is from outside of this forum
        netresec@infosec.exchange
        wrote last edited by
        #3

        This sample is classified as ValleyRAT on ANY.RUN, but the C2 doesn't look like ValleyRAT either
        https://app.any.run/tasks/ca8080c4-8dc8-4107-b261-f16a69e5dac1/

        netresec@infosec.exchangeN 1 Reply Last reply
        0
        • netresec@infosec.exchangeN netresec@infosec.exchange

          This sample is classified as ValleyRAT on ANY.RUN, but the C2 doesn't look like ValleyRAT either
          https://app.any.run/tasks/ca8080c4-8dc8-4107-b261-f16a69e5dac1/

          netresec@infosec.exchangeN This user is from outside of this forum
          netresec@infosec.exchangeN This user is from outside of this forum
          netresec@infosec.exchange
          wrote last edited by
          #4

          Sample on Triage with the same C2:
          https://tria.ge/260207-p7n72aft4c

          netresec@infosec.exchangeN 1 Reply Last reply
          1
          0
          • netresec@infosec.exchangeN netresec@infosec.exchange

            Sample on Triage with the same C2:
            https://tria.ge/260207-p7n72aft4c

            netresec@infosec.exchangeN This user is from outside of this forum
            netresec@infosec.exchangeN This user is from outside of this forum
            netresec@infosec.exchange
            wrote last edited by
            #5

            Found two more C2 servers with the same Accept: */* and frAQBc8Wsa1xVPfvJcrgRYwTiizs2tr strings. These ones run on TCP 5050 as well.
            👾 192.253.229.223:5050 (last active December 2025)
            👾 156.254.20.94:5050 (last active December 2025)

            #Threatintel

            Link Preview Image
            netresec@infosec.exchangeN 1 Reply Last reply
            1
            0
            • netresec@infosec.exchangeN netresec@infosec.exchange

              Found two more C2 servers with the same Accept: */* and frAQBc8Wsa1xVPfvJcrgRYwTiizs2tr strings. These ones run on TCP 5050 as well.
              👾 192.253.229.223:5050 (last active December 2025)
              👾 156.254.20.94:5050 (last active December 2025)

              #Threatintel

              Link Preview Image
              netresec@infosec.exchangeN This user is from outside of this forum
              netresec@infosec.exchangeN This user is from outside of this forum
              netresec@infosec.exchange
              wrote last edited by
              #6

              192.253.229.223:5050 on Triage
              https://tria.ge/251217-cgb4kafr9y

              netresec@infosec.exchangeN 1 Reply Last reply
              0
              • netresec@infosec.exchangeN netresec@infosec.exchange

                192.253.229.223:5050 on Triage
                https://tria.ge/251217-cgb4kafr9y

                netresec@infosec.exchangeN This user is from outside of this forum
                netresec@infosec.exchangeN This user is from outside of this forum
                netresec@infosec.exchange
                wrote last edited by
                #7

                156.254.20.94:5050 on ANY.RUN
                https://app.any.run/tasks/31811332-56ec-4fff-a134-43a1a699cfc8

                1 Reply Last reply
                1
                0
                • R relay@relay.infosec.exchange shared this topic
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • World
                • Users
                • Groups