Showing posts with label C2. Show all posts
Showing posts with label C2. Show all posts

Friday, 22 September 2017

CCleaner Command and Control Causes Concern

Introduction


Talos recently published a technical analysis of a backdoor which was included with version 5.33 of the CCleaner application. During our investigation we were provided an archive containing files that were stored on the C2 server. Initially, we had concerns about the legitimacy of the files. However, we were able to quickly verify that the files were very likely genuine based upon the web server configuration files and the fact that our research activity was reflected in the contents of the MySQL database included in the archived files.