Coverage record · Guided evaluation

C2Looper

This record covers one GitHub-C2 Windows DLL variant. Proofmetry offers guided evaluations for compatible samples, with available predefined behavior tests confirmed during the demo process.

Variant boundary: A C2Looper family label or the eight-handler research map does not establish support for every build, handler, or behavior test.

Record metadata

Analyzed variant and preview status

Evidence vocabulary

Proofmetry Evidence Status

Each statement stops at the highest level supported by the available research. Not every researched or preview behavior reaches the final level.

  1. 01

    Mapped

    A behavior or handler was identified through analysis.

  2. 02

    Path reached

    Execution entered the intended code path.

  3. 03

    Result observed

    A meaningful intermediate or returned result was observed.

  4. 04

    Terminal state observed

    The workflow reached a defined completion or stop condition.

  5. 05

    Endpoint effect confirmed

    The intended native endpoint or network effect was corroborated.

Research evidence

Evidence matrix

The published counts describe research. They are not an inventory of customer-facing tests.

Evidence status and claim boundaries for the analyzed C2Looper variant
Research itemPublic evidenceClaim boundary
Command handlersMapped: eight handlers identified through static analysis.Mapping does not establish dynamic completion or product availability.
Isolated executionPath reached / observed: seven handler paths were observed.The public brief does not assign one aggregate endpoint-confirmation count to those paths.
Directory enumerationMapped: identified through analysis.Static-only; no dynamic confirmation is claimed.
Local-memory executionResult observed: the private-memory fallback ran inside the existing backdoor process.The alternate module-overloading path remained mapped-only; neither path targeted another process.
Redirected network activityResult observed: network activity completed in the isolated environment.Network completion did not prove host-side success; one handler could still report failure.

Behavior categories

What the research reached

The original C2Looper sample—not a substitute simulator—produced the observed behavior.

Discovery

Identity, network, domain, group, installed-software, and drive context appeared in the observed process lineage. Directory enumeration remained static-only.

File operations

The observed host effect included inbound retrieval and a temporary-file write. Direction and endpoint effect matter more than the handler label.

Process execution

The sample produced process activity, including Windows command children during discovery.

Local memory

The observed fallback used private memory, changed protection from read-write to read-execute, and started a local thread in the backdoor process.

Network behavior

Traffic was redirected to internal research infrastructure; GitHub and attacker-controlled infrastructure were not contacted.

Availability boundary: These categories summarize research evidence. The predefined tests available for a compatible customer-held sample are confirmed during the evaluation process.

Known limitations

Keep conclusions pinned to this variant and evidence.

  • The findings apply to one C2Looper Windows DLL and the paths mapped or observed during this research.
  • They do not establish behavior for every C2Looper version, environment, rule, model, or security product.
  • Directory enumeration remained static-only, and the alternate module-overloading path remained mapped-only.
  • Eight mapped handlers and seven observed paths do not mean eight or seven customer-facing behavior tests are available.
  • Detection and model outcomes depend on customer sensors, configuration, collection, and evaluation criteria.
  • Customer-collected telemetry from one run is not automatically representative, balanced, sufficient for training, or likely to improve model performance.

Revision history

Coverage record changes

C2Looper public coverage record revision history
DateRecordChange
August 30, 2026Website coverage record 1.0Initial public coverage record separating Research Brief 001, revision 1.2, from current guided-evaluation availability. This record number is not a Threat Pack version.

Guided evaluation

See whether this C2Looper coverage fits your workflow.

We confirm the sample or compatible variant, selected behavior test, and evidence objective before a run.

Get a demo