Discovery
Identity, network, domain, group, installed-software, and drive context appeared in the observed process lineage. Directory enumeration remained static-only.
Coverage record · Guided evaluation
This record covers one GitHub-C2 Windows DLL variant. Proofmetry offers guided evaluations for compatible samples, with available predefined behavior tests confirmed during the demo process.
Variant boundary: A C2Looper family label or the eight-handler research map does not establish support for every build, handler, or behavior test.
Record metadata
Evidence vocabulary
Each statement stops at the highest level supported by the available research. Not every researched or preview behavior reaches the final level.
A behavior or handler was identified through analysis.
Execution entered the intended code path.
A meaningful intermediate or returned result was observed.
The workflow reached a defined completion or stop condition.
The intended native endpoint or network effect was corroborated.
Research evidence
The published counts describe research. They are not an inventory of customer-facing tests.
| Research item | Public evidence | Claim boundary |
|---|---|---|
| Command handlers | Mapped: eight handlers identified through static analysis. | Mapping does not establish dynamic completion or product availability. |
| Isolated execution | Path reached / observed: seven handler paths were observed. | The public brief does not assign one aggregate endpoint-confirmation count to those paths. |
| Directory enumeration | Mapped: identified through analysis. | Static-only; no dynamic confirmation is claimed. |
| Local-memory execution | Result observed: the private-memory fallback ran inside the existing backdoor process. | The alternate module-overloading path remained mapped-only; neither path targeted another process. |
| Redirected network activity | Result observed: network activity completed in the isolated environment. | Network completion did not prove host-side success; one handler could still report failure. |
Behavior categories
The original C2Looper sample—not a substitute simulator—produced the observed behavior.
Identity, network, domain, group, installed-software, and drive context appeared in the observed process lineage. Directory enumeration remained static-only.
The observed host effect included inbound retrieval and a temporary-file write. Direction and endpoint effect matter more than the handler label.
The sample produced process activity, including Windows command children during discovery.
The observed fallback used private memory, changed protection from read-write to read-execute, and started a local thread in the backdoor process.
Traffic was redirected to internal research infrastructure; GitHub and attacker-controlled infrastructure were not contacted.
Availability boundary: These categories summarize research evidence. The predefined tests available for a compatible customer-held sample are confirmed during the evaluation process.
Known limitations
Revision history
| Date | Record | Change |
|---|---|---|
| August 30, 2026 | Website coverage record 1.0 | Initial public coverage record separating Research Brief 001, revision 1.2, from current guided-evaluation availability. This record number is not a Threat Pack version. |
Guided evaluation
We confirm the sample or compatible variant, selected behavior test, and evidence objective before a run.
Get a demo