• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    C2Looper Backdoor Shell Output Capture via c2_out.txt

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Duo Tech@duotech
    •updated Aug 18, 2026•2•0•8

    Detects C2Looper's remote interactive shell and ShellExecuteW run-and-self-delete command execution, correlated with the c2_out.txt output-capture artifact.

    Sigma

    Tags

    T1059 - Command and Scripting InterpreterT1059.003 - Windows Command ShellT1005 - Data from Local SystemT1070.004 - File DeletionTA0002 - ExecutionTA0009 - CollectionTA0005 - StealthExecutionFile EventWindowsWindows Command ShellPowerShellattack.t1059attack.t1059.003attack.t1005attack.t1070.004

    Found in

    • C2Looper: Rust-Based Backdoor Utilizing GitHub for C2Last updated Aug 18, 2026

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?