ThreatFox IOC Database
You are viewing the ThreatFox database entry for url http://d30bham075f6wf.cloudfront.net:80/jquery-3.3.1.min.js.
Database Entry
This IOC expired
This IOC is an old IOC and hence has expired on 2026-09-11 01:15:01 UTC. We therefore refrain from exporting it into our datasets. As a result, this database entry is purely informational and has no impact.
| IOC ID: | 200521 |
|---|---|
| IOC: | http://d30bham075f6wf.cloudfront.net:80/jquery-3.3.1.min.js |
| IOC Type : | url |
| Threat Type : | botnet_cc |
| Malware: | Cobalt Strike |
| Malware alias: | Agentemis, BEACON, CobaltStrike, cobeacon |
| Confidence Level : | Confidence level is high (100%) |
| Is compromised? : | False |
| ASN: | AS16509 AMAZON-02 |
| Country: | US |
| First seen: | 2021-08-27 07:21:40 UTC |
| Last seen: | never |
| UUID: | 6c8d4665-0707-11ec-830d-42010aa4000a |
| Reporter | |
| Reward |
10 credits from lazyactivist192 |
| Tags: | CobaltStrike |
NexusFuzzy
[ Download URL of Beacon ]http://3.236.77.121/
[ Extracted Beacon Config ]
BeaconType: ['HTTP']
Port: 80
SleepTime: 45000
MaxGetSize: 1403644
Jitter: 37
MaxDNS: Not Found
PublicKey: b'0\x81\x9f0\r\x06\t*\x86H\x86\xf7\r\x01\x01\x01\x05\x00\x03\x81\x8d\x000\x81\x89\x02\x81\x81\x00\x95\xf5\xccY\x00\xbc&\x98I\x10!\xccb\\7\xde\xcbs\xab\xa4H\xed\x05bq\x16\xe5\xae\x02\xf4\x1c\xe6\xf2o\x9c\xfdP\xe0"\xdf\x98\x9e\x7fH$\xd4\xee\xd5\xc4\x161\x12\xef\xfc\x16\x0f\x0b\xc6\x86\xdf\x01\xc7[\xc8\xc0v\xab\xb4\xeb\xd7R\x05\xef\xd6\xb3b\xca\n\xbf\x88\xa9\xa2p\xe7\x08\x9d\xcd(\xeaWG=\xed\xb1\xe8\xb8\xf7\x18N\x00\x07\x85\xcb\xb7\xc4g\xfcS\xb5\xf1<G6\xd6\xc9O\x0c\xd6\x93\xcd\x82\xe9J\x92\xeevn\xf9\x02\x03\x01\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
PublicKey_MD5: 401ff10a9e585d3ced0eac2cbaa044e4
C2Server: d30bham075f6wf.cloudfront.net,/jquery-3.3.1.min.js
UserAgent: Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko
HttpPostUri: /jquery-3.3.2.min.js
Malleable_C2_Instructions: ['Remove 1522 bytes from the end', 'Remove 84 bytes from the beginning', 'Remove 3931 bytes from the beginning', 'Base64 URL-safe decode', 'XOR mask w/ random key']
HttpGet_Metadata: {'ConstHeaders': ['Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8', 'Referer: http://code.jquery.com/', 'Accept-Encoding: gzip, deflate'], 'ConstParams': [], 'Metadata': ['base64url', 'prepend "__cfduid="', 'header "Cookie"'], 'SessionId': [], 'Output': []}
HttpPost_Metadata: {'ConstHeaders': ['Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8', 'Referer: http://code.jquery.com/', 'Accept-Encoding: gzip, deflate'], 'ConstParams': [], 'Metadata': [], 'SessionId': ['mask', 'base64url', 'parameter "__cfduid"'], 'Output': ['mask', 'base64url', 'print']}
SpawnTo: b'\x06\xa8\xc6\x91\xe3c\x0b\xc2\xeda\x15\xfc`\xfenj'
PipeName: Not Found
DNS_Idle: Not Found
DNS_Sleep: Not Found
SSH_Host: Not Found
SSH_Port: Not Found
SSH_Username: Not Found
SSH_Password_Plaintext: Not Found
SSH_Password_Pubkey: Not Found
SSH_Banner:
HttpGet_Verb: GET
HttpPost_Verb: POST
HttpPostChunk: 0
Spawnto_x86: %windir%\syswow64\dllhost.exe
Spawnto_x64: %windir%\sysnative\dllhost.exe
CryptoScheme: 0
Proxy_Config: Not Found
Proxy_User: Not Found
Proxy_Password: Not Found
Proxy_Behavior: Use IE settings
Watermark: 836532390
bStageCleanup: True
bCFGCaution: False
KillDate: 0
bProcInject_StartRWX: False
bProcInject_UseRWX: False
bProcInject_MinAllocSize: 17500
ProcInject_PrependAppend_x86: [b'\x90\x90', 'Empty']
ProcInject_PrependAppend_x64: [b'\x90\x90', 'Empty']
ProcInject_Execute: ['ntdll:RtlUserThreadStart', 'CreateThread', 'NtQueueApcThread-s', 'CreateRemoteThread', 'RtlCreateUserThread']
ProcInject_AllocationMethod: NtMapViewOfSection
ProcInject_Stub: b'\xb2so\x1c\xbb\xa9\rB(o\xc4+\xfb\xa7OM'
bUsesCookies: True
HostHeader:
smbFrameHeader: b'\x00\x05\x80\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
tcpFrameHeader: b'\x00\x05\x80\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
headersToRemove: Not Found
DNS_Beaconing: Not Found
DNS_get_TypeA: Not Found
DNS_get_TypeAAAA: Not Found
DNS_get_TypeTXT: Not Found
DNS_put_metadata: Not Found
DNS_put_output: Not Found
DNS_resolver: Not Found
DNS_strategy: round-robin
DNS_strategy_rotate_seconds: -1
DNS_strategy_fail_x: -1
DNS_strategy_fail_seconds: -1
US