check this exe quick fast and tell me doest it con...

创建于:2026年9月3日

使用 GPT-5.6 Thinking 回答 Chat01

问题

uac-bypass-new.exe

check this exe quick fast and tell me doest it connect back to any c2 server if yes tell me the ip of the attacker and port cery fast

思考

Analyzed UAC bypass executable and extracted C2 indicators

Worked for 37s

回答

Fast static check: I do not see evidence that this EXE connects to a C2 server.

  • C2 IP: none found
  • C2 port: none found
  • No WS2_32, WinHTTP, or WinINet networking imports.
  • No literal IPv4 addresses or HTTP/HTTPS URLs embedded.
  • rsproxy.cn appears only inside a Rust build/source path, not as a runtime connection target.
  • The binary appears focused on a CMSTP-based UAC bypass, invoking cmstp.exe / cmd.exe.
  • SHA-256: 202a42886260de6223c5a5201f951a4c0d890cc294f4fa537108221c8d040dff

So there is currently no attacker IP/port I can give you from this sample. An encrypted or runtime-generated C2 could still evade a quick static scan.

分享这个问答