COMBOS - Possible infection

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The COMBOS is a backdoor uses a set of commands transmitted over HTTP in communication with its C2 server.
ref. http://intelreport.mandiant.com/Mandiant_APT1_Report_Appendix.zip p.37