ThreatFox IOC Database
You are viewing the ThreatFox database entry for url https://fedex-global.com:443/MicrosoftUpdate/ShellEx/KB242742/default.aspx.
Database Entry
This IOC expired
This IOC is an old IOC and hence has expired on 2026-09-13 01:15:01 UTC. We therefore refrain from exporting it into our datasets. As a result, this database entry is purely informational and has no impact.
| IOC ID: | 201053 |
|---|---|
| IOC: | https://fedex-global.com:443/MicrosoftUpdate/ShellEx/KB242742/default.aspx |
| IOC Type : | url |
| Threat Type : | botnet_cc |
| Malware: | Cobalt Strike |
| Malware alias: | Agentemis, BEACON, CobaltStrike, cobeacon |
| Confidence Level : | Confidence level is high (100%) |
| Is compromised? : | False |
| First seen: | 2021-08-27 15:48:18 UTC |
| Last seen: | never |
| UUID: | 3304a557-074e-11ec-830d-42010aa4000a |
| Reporter | |
| Reward |
10 credits from lazyactivist192 |
| Tags: | CobaltStrike |
NexusFuzzy
[ Download URL of Beacon ]https://128.199.0.91:443/
[ Extracted Beacon Config ]
BeaconType: ['HTTPS']
Port: 443
SleepTime: 500
MaxGetSize: 1048576
Jitter: 0
MaxDNS: Not Found
PublicKey: b"0\x81\x9f0\r\x06\t*\x86H\x86\xf7\r\x01\x01\x01\x05\x00\x03\x81\x8d\x000\x81\x89\x02\x81\x81\x00\xa0*\xd3fW\xabEas\xfe\x9ak\xc4\xf8\xdd\x8e'\x85\xcf/\xcd\xb5\xda\xa49gO\x0c\xfb\x8eM\x0e\xef\x9a\x15\t1\x8c\x12h,J\xa1N\x0e\xb5\xf7\xf2\xffE@9`Y\x97:\xd7\x88\xbd+\x8eD\xb7d\xff\xf2N\xb9\xcf\xc8\xdaU\x17\x9e\x13[\xe3\xa3\xf0r\x0f\x9d\xdan\xa4p03 \x13\xedED\xaa\x86\xa5\xe4\xd2\xb8>d\xf5\x1d\x1a\xa6c\xdf~\xebV\x079:v<\xa4\xb5.\x03\xf6\xd3\x8b$\xa09\x8c\xcc\x11\x02\x03\x01\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
PublicKey_MD5: 311ba4a8b37a67c105a9c8b67bd132ea
C2Server: fedex-global.com,/MicrosoftUpdate/ShellEx/KB242742/default.aspx
UserAgent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)
HttpPostUri: /MicrosoftUpdate/GetUpdate/KB
Malleable_C2_Instructions: []
HttpGet_Metadata: {'ConstHeaders': ['User-Agent: Mozilla/4.0 (Compatible; MSIE 6.0;Windows NT 5.1)', 'Accept: */*, ..., ......, .'], 'ConstParams': [], 'Metadata': ['netbiosu', 'parameter "tmp"'], 'SessionId': [], 'Output': []}
HttpPost_Metadata: {'ConstHeaders': ['Content-Type: application/octet-stream', 'User-Agent: Mozilla/4.0 (Compatible; MSIE 6.0;Windows NT 5.1)'], 'ConstParams': [], 'Metadata': [], 'SessionId': ['append "/default.asp"', 'uri_append'], 'Output': ['print']}
SpawnTo: b'\x81F\xd6<\xf9\x17R\xd6y^\x92\x95\xad\x81\x89\t'
PipeName: Not Found
DNS_Idle: Not Found
DNS_Sleep: Not Found
SSH_Host: Not Found
SSH_Port: Not Found
SSH_Username: Not Found
SSH_Password_Plaintext: Not Found
SSH_Password_Pubkey: Not Found
SSH_Banner:
HttpGet_Verb: GET
HttpPost_Verb: POST
HttpPostChunk: 0
Spawnto_x86: %windir%\syswow64\rundll32.exe
Spawnto_x64: %windir%\sysnative\rundll32.exe
CryptoScheme: 0
Proxy_Config: Not Found
Proxy_User: Not Found
Proxy_Password: Not Found
Proxy_Behavior: Use IE settings
Watermark: 401466503
bStageCleanup: False
bCFGCaution: False
KillDate: 0
bProcInject_StartRWX: True
bProcInject_UseRWX: True
bProcInject_MinAllocSize: 0
ProcInject_PrependAppend_x86: Empty
ProcInject_PrependAppend_x64: Empty
ProcInject_Execute: ['CreateThread', 'SetThreadContext', 'CreateRemoteThread', 'RtlCreateUserThread']
ProcInject_AllocationMethod: VirtualAllocEx
ProcInject_Stub: b'\xb5J\xfe\x01\xecju\xed\xf3^\x1aD\xf8\xbd9)'
bUsesCookies: False
HostHeader:
smbFrameHeader: b'\x00\x04\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
tcpFrameHeader: b'\x00\x04\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
headersToRemove: Not Found
DNS_Beaconing: Not Found
DNS_get_TypeA: Not Found
DNS_get_TypeAAAA: Not Found
DNS_get_TypeTXT: Not Found
DNS_put_metadata: Not Found
DNS_put_output: Not Found
DNS_resolver: Not Found
DNS_strategy: Not Found
DNS_strategy_rotate_seconds: Not Found
DNS_strategy_fail_x: Not Found
DNS_strategy_fail_seconds: Not Found