🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://d1yxgunqlbb2ab.cloudfront.net:443/jquery-3.3.1.min.js.

Database Entry


IOC ID:200702
IOC: https://d1yxgunqlbb2ab.cloudfront.net:443/jquery-3.3.1.min.js
IOC Type :url
Threat Type :botnet_cc
Malware: Cobalt Strike
Malware alias:Agentemis, BEACON, CobaltStrike, cobeacon
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS16509 AMAZON-02
Country:- US
First seen:2021-08-27 08:10:37 UTC
Last seen:never
UUID:432b6fb1-070e-11ec-830d-42010aa4000a
Reporter NexusFuzzy
Reward 10 credits from lazyactivist192
Tags:CobaltStrike

Avatar
NexusFuzzy
[ Download URL of Beacon ]
https://3.95.132.134/
[ Extracted Beacon Config ]
BeaconType: ['HTTPS']
Port: 443
SleepTime: 45000
MaxGetSize: 1403644
Jitter: 37
MaxDNS: Not Found
PublicKey: b'0\x81\x9f0\r\x06\t*\x86H\x86\xf7\r\x01\x01\x01\x05\x00\x03\x81\x8d\x000\x81\x89\x02\x81\x81\x00\x9d\xe8DL\x90\xed\xd5\xa2\xe4\xab\x8c\xee\xbf\xc9=\xf6\xda\x96\xc3H\xbd\x93<x\xe2/6\xb3\xa6?WP\xac\xbd8\x91\xdegl\x98\xbfq\xa9\\\x11\xd2\t\x1a\xe5I\xbe\x98\xce\xc6\xf1\x88\xb4^~\xe9\x110\xa2N\xc4\n\xdf\xed=j\xc3\x8a\xff\xce\xb2\xb6\xf9bcl\xf3\xf0\xaa\xf6\xd7\xea\x95?\xf0\xf5\xabG:\xfa\xeaZKK\xd1v!\xda\xc7\xe3\xf0cHT\xbeh(\xe8v\xed\xc3\xbc\xb3G\xbe>\xb3\xe9L"\xd0\x03r\xff\x02\x03\x01\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
PublicKey_MD5: 614cfda6da56bae676d0275ca187f6b2
C2Server: d1yxgunqlbb2ab.cloudfront.net,/jquery-3.3.1.min.js
UserAgent: Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko
HttpPostUri: /jquery-3.3.2.min.js
Malleable_C2_Instructions: ['Remove 1522 bytes from the end', 'Remove 84 bytes from the beginning', 'Remove 3931 bytes from the beginning', 'Base64 URL-safe decode', 'XOR mask w/ random key']
HttpGet_Metadata: {'ConstHeaders': ['Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8', 'Referer: http://code.jquery.com/', 'Accept-Encoding: gzip, deflate'], 'ConstParams': [], 'Metadata': ['base64url', 'prepend "__cfduid="', 'header "Cookie"'], 'SessionId': [], 'Output': []}
HttpPost_Metadata: {'ConstHeaders': ['Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8', 'Referer: http://code.jquery.com/', 'Accept-Encoding: gzip, deflate'], 'ConstParams': [], 'Metadata': [], 'SessionId': ['mask', 'base64url', 'parameter "__cfduid"'], 'Output': ['mask', 'base64url', 'print']}
SpawnTo: b"\xa7N\xee\x8e\xb3\xdaV,?'\xa9\xb5\xc7{\x7f|"
PipeName: Not Found
DNS_Idle: Not Found
DNS_Sleep: Not Found
SSH_Host: Not Found
SSH_Port: Not Found
SSH_Username: Not Found
SSH_Password_Plaintext: Not Found
SSH_Password_Pubkey: Not Found
SSH_Banner: Host: d1yxgunqlbb2ab.cloudfront.net

HttpGet_Verb: GET
HttpPost_Verb: POST
HttpPostChunk: 0
Spawnto_x86: %windir%\syswow64\dllhost.exe
Spawnto_x64: %windir%\sysnative\dllhost.exe
CryptoScheme: 0
Proxy_Config: Not Found
Proxy_User: Not Found
Proxy_Password: Not Found
Proxy_Behavior: Use IE settings
Watermark: 2101893364
bStageCleanup: True
bCFGCaution: False
KillDate: 0
bProcInject_StartRWX: False
bProcInject_UseRWX: False
bProcInject_MinAllocSize: 17500
ProcInject_PrependAppend_x86: [b'\x90\x90', 'Empty']
ProcInject_PrependAppend_x64: [b'\x90\x90', 'Empty']
ProcInject_Execute: ['ntdll:RtlUserThreadStart', 'CreateThread', 'NtQueueApcThread-s', 'CreateRemoteThread', 'RtlCreateUserThread']
ProcInject_AllocationMethod: NtMapViewOfSection
ProcInject_Stub: b'\xb2so\x1c\xbb\xa9\rB(o\xc4+\xfb\xa7OM'
bUsesCookies: True
HostHeader: Host: d1yxgunqlbb2ab.cloudfront.net

smbFrameHeader: b'\x00\x05\x80\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
tcpFrameHeader: b'\x00\x05\x80\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
headersToRemove: Not Found
DNS_Beaconing: Not Found
DNS_get_TypeA: Not Found
DNS_get_TypeAAAA: Not Found
DNS_get_TypeTXT: Not Found
DNS_put_metadata: Not Found
DNS_put_output: Not Found
DNS_resolver: Not Found
DNS_strategy: round-robin
DNS_strategy_rotate_seconds: -1
DNS_strategy_fail_x: -1
DNS_strategy_fail_seconds: -1