🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://dcrwaxwvb1lj1.cloudfront.net/safebrowsing/QepEF3u/lpIbUDDDMuQakD28VbLjw7sqwIHX0CVUV.

Database Entry


IOC ID:1067781
IOC: https://dcrwaxwvb1lj1.cloudfront.net/safebrowsing/QepEF3u/lpIbUDDDMuQakD28VbLjw7sqwIHX0CVUV
IOC Type :url
Threat Type :botnet_cc
Malware: Cobalt Strike
Malware alias:Agentemis, BEACON, CobaltStrike, cobeacon
Confidence Level : Confidence level is high (100%)
Is compromised? : False
First seen:2023-01-12 04:25:22 UTC
Last seen:never
UUID:2131af3a-9231-11ed-8c16-42010aa4000a
Reporter drb_ra
Reward 5 credits from ThreatFox
Tags:CobaltStrike DIGITALOCEAN-ASN

Avatar
drb_ra
Cobalt Strike Server Found
C2: HTTPS @ 157[.]245[.]102[.]164:443
C2 Server: dcrwaxwvb1lj1[.]cloudfront[.]net,/safebrowsing/QepEF3u/lpIbUDDDMuQakD28VbLjw7sqwIHX0CVUV
POST URI: /safebrowsing/v9wu3sFz/5M-90uv86SNtYhxPJUeHAVTuF7Rq9B39RN
Country: India
ASN: DIGITALOCEAN-ASN
Host Header: dcrwaxwvb1lj1[.]cloudfront[.]net