ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain cs.xcb.one.

Database Entry


IOC ID:1224105
IOC: cs.xcb.one
IOC Type :domain
Threat Type :botnet_cc
Malware: Cobalt Strike
Malware alias:Agentemis, BEACON, CobaltStrike, cobeacon
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS132203 TENCENT-NET-AP-CN
Country:- CN
First seen:2023-12-27 22:15:29 UTC
Last seen:2026-06-10 15:00:55 UTC
UUID:7173d4cb-a505-11ee-a7e8-42010aa4000a
Reporter drb_ra
Reward 5 credits from ThreatFox
Tags:CobaltStrike cs-watermark-987654321 MICROSOFT-CORP-MSN-AS-BLOCK

Avatar
drb_ra
Cobalt Strike Server Found
C2: HTTPS @ 20[.]196[.]198[.]116:443
C2 Server: 20[.]196[.]198[.]116,/Level/printenv/D2UDLM17,cs[.]xcb[.]one,/Level/printenv/D2UDLM17
POST URI: /setup/v8[.]76/G9TAXES4T8PR
Country: South Korea
ASN: MICROSOFT-CORP-MSN-AS-BLOCK