ThreatFox IOC Database
You are viewing the ThreatFox database entry for url http://d2g37k1rs1nihw.cloudfront.net:80/w/api.php.
Database Entry
This IOC expired
This IOC is an old IOC and hence has expired on 2026-09-11 01:15:01 UTC. We therefore refrain from exporting it into our datasets. As a result, this database entry is purely informational and has no impact.
| IOC ID: | 200760 |
|---|---|
| IOC: | http://d2g37k1rs1nihw.cloudfront.net:80/w/api.php |
| IOC Type : | url |
| Threat Type : | botnet_cc |
| Malware: | Cobalt Strike |
| Malware alias: | Agentemis, BEACON, CobaltStrike, cobeacon |
| Confidence Level : | Confidence level is high (100%) |
| Is compromised? : | False |
| ASN: | AS16509 AMAZON-02 |
| Country: | US |
| First seen: | 2021-08-27 08:24:21 UTC |
| Last seen: | never |
| UUID: | 2ddbf516-0710-11ec-830d-42010aa4000a |
| Reporter | |
| Reward |
10 credits from lazyactivist192 |
| Tags: | CobaltStrike |
NexusFuzzy
[ Download URL of Beacon ]http://3.89.133.68/
[ Extracted Beacon Config ]
BeaconType: ['HTTP']
Port: 80
SleepTime: 5000
MaxGetSize: 1398342
Jitter: 20
MaxDNS: Not Found
PublicKey: b'0\x81\x9f0\r\x06\t*\x86H\x86\xf7\r\x01\x01\x01\x05\x00\x03\x81\x8d\x000\x81\x89\x02\x81\x81\x00\x89?K\xdc\x15\x9b\xd6\xa6\xf3\xe0\x0f\x7f\x19I\xd5\x9a\xca\xdd:\\h\xect\xc4*\xd9\xb9\x82\xf4\xc8\x15\xb5\x11\xebA\xcdEze\xc3\x86S\x9a\xdf\xd7\xd9\x04>\x8ai\xc5\xea\xca\xc1v\xb4\xd1<\x8dT6\t.|\x07\xbb\xb0\xfcb\x03\xfff\x1dw:\xfc\xaej\xca\xab\xc4Zn\x01> \xfd\xdfg\xc8|*;h\xac\xcb\xdf\xcf\x92\xe5\xae\x8d\x96\x90vckP\xaf\x14j`\xc2\xef\x8a\xe1\xe0q\xafk1\xe8\xc0w\x19\x86\x9d#\x02\x03\x01\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
PublicKey_MD5: f4df74a088c937c13d87e4509e4a5989
C2Server: d2g37k1rs1nihw.cloudfront.net,/w/api.php
UserAgent: Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko
HttpPostUri: /wiki
Malleable_C2_Instructions: ['Remove 192 bytes from the end', 'Remove 48 bytes from the beginning', 'Base64 URL-safe decode']
HttpGet_Metadata: {'ConstHeaders': ['Host: d2g37k1rs1nihw.cloudfront.net', 'Accept: text/html'], 'ConstParams': ['action=opensearch', 'format=json', 'namespace=0'], 'Metadata': ['base64url', 'prepend "YmFzzYmTGI2YZk"', 'parameter "search"'], 'SessionId': [], 'Output': []}
HttpPost_Metadata: {'ConstHeaders': ['Host: d2g37k1rs1nihw.cloudfront.net', 'Accept: text/html;'], 'ConstParams': [], 'Metadata': [], 'SessionId': ['netbiosu', 'prepend "53A32"', 'header "X-Crsf-Token"'], 'Output': ['netbiosu', 'prepend "image="', 'append "&namespace=0&limit=2&suggest=true"', 'print']}
SpawnTo: b'R0\xfdl E>5\xca.\xa2L\x03\x8a\xaa7'
PipeName: Not Found
DNS_Idle: Not Found
DNS_Sleep: Not Found
SSH_Host: Not Found
SSH_Port: Not Found
SSH_Username: Not Found
SSH_Password_Plaintext: Not Found
SSH_Password_Pubkey: Not Found
SSH_Banner:
HttpGet_Verb: GET
HttpPost_Verb: POST
HttpPostChunk: 0
Spawnto_x86: %windir%\syswow64\rundll32.exe
Spawnto_x64: %windir%\sysnative\rundll32.exe
CryptoScheme: 0
Proxy_Config: Not Found
Proxy_User: Not Found
Proxy_Password: Not Found
Proxy_Behavior: Use IE settings
Watermark: 421647742
bStageCleanup: False
bCFGCaution: False
KillDate: 0
bProcInject_StartRWX: True
bProcInject_UseRWX: True
bProcInject_MinAllocSize: 0
ProcInject_PrependAppend_x86: Empty
ProcInject_PrependAppend_x64: Empty
ProcInject_Execute: ['CreateThread', 'SetThreadContext', 'CreateRemoteThread', 'RtlCreateUserThread']
ProcInject_AllocationMethod: VirtualAllocEx
ProcInject_Stub: b'"+\x8f\'\xdb\xdf\xba\x8d\xddU\x9e\xec\xa2~\xa6H'
bUsesCookies: False
HostHeader:
smbFrameHeader: b'\x00\x04\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
tcpFrameHeader: b'\x00\x04\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
headersToRemove: Not Found
DNS_Beaconing: Not Found
DNS_get_TypeA: Not Found
DNS_get_TypeAAAA: Not Found
DNS_get_TypeTXT: Not Found
DNS_put_metadata: Not Found
DNS_put_output: Not Found
DNS_resolver: Not Found
DNS_strategy: round-robin
DNS_strategy_rotate_seconds: -1
DNS_strategy_fail_x: -1
DNS_strategy_fail_seconds: -1
US