BISCUIT - 'svchost.exe does not exist' - ctfmon.exe

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

BISCUIT communicates using a custom protocol, which is then encrypted using SSL. Once installed BISCUIT will attempt to beacon to its
command/control servers approximately every 10 or 30 minutes. It will beacon to its primary server first, followed by a secondary server.
All communication is encrypted with SSL (OpenSSL 0.9.8i).
ref. http://intelreport.mandiant.com/Mandiant_APT1_Report_Appendix.zip p.19