WEBC2-TABLE (269fee27-f275-44e9-a0db-bebf14d2f83c)
The WEBC2 malware family is designed to retrieve a Web page from a pre-determined C2 server. It expects the Web page to contain special HTML tags; the backdoor will attempt to interpret the data between the tags as commands. The WEBC2-TABLE variant looks for web pages containing 'background', 'align', and 'bgcolor' tags to be present in the requested Web page. If the data in these tags are formatted correctly, the malware will decode a second URL and a filename. This URL is then retrieved, written to the decoded filename and executed.
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
WEBC2-TABLE (269fee27-f275-44e9-a0db-bebf14d2f83c) | Tool | WebC2-Table (1035ea6f-6743-4e69-861c-454c19ec96ae) | Malpedia | 1 |