🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://d1rsx3ll433ur2.cloudfront.net:443/s/ref=nb_sb_noss_1/167-3294888-026249/field-keywords=year.

Database Entry


IOC ID:300797
IOC: https://d1rsx3ll433ur2.cloudfront.net:443/s/ref=nb_sb_noss_1/167-3294888-026249/field-keywords=year
IOC Type :url
Threat Type :botnet_cc
Malware: Cobalt Strike
Malware alias:Agentemis, BEACON, CobaltStrike, cobeacon
Confidence Level : Confidence level is moderate (50%)
Is compromised? : False
First seen:2022-01-19 08:35:27 UTC
Last seen:never
UUID:c09f4033-7902-11ec-8ab6-42010aa4000a
Reporter NexusFuzzy
Reward 5 credits from ThreatFox
Tags:CobaltStrike

Avatar
NexusFuzzy
[ Download URL of Beacon ]
https://3.232.99.110:443/
[ Extracted Beacon Config ]
BeaconType: ['HTTPS']
Port: 443
SleepTime: 5000
MaxGetSize: 1048576
Jitter: 0
MaxDNS: Not Found
PublicKey: b'0\x81\x9f0\r\x06\t*\x86H\x86\xf7\r\x01\x01\x01\x05\x00\x03\x81\x8d\x000\x81\x89\x02\x81\x81\x00\xa5u\xfb~;1Ef\xf1\xd7eh^\xe7\x9d\xab-d\x175\x96N\x8fyq\x9f\xd3\xbd\\\xde2\xcbc\x1a\xd5H\x86\x01\x03W5\xa4\xb6)_\x98C\xb5\xeb\x04$\xd1\xef;\xb4\xf0\xc5P\x11CDt\xe4\x19k\t_\x93N\xe7\x03\x1aU\xcd\x95\x9a\x9f/Y\x88B\n.\xef\xa8:]\x8aH\xbf\xd3\x9c\x15\x01\xd0\xbf\xb9\xedsZ\xb5s\xc2\xb3\xf6\xbd\xd7\xf0\x9eF\xd2u\x1f\x11\x86 aJ\xe4\x03\xc3~\x1dz\xbb\xe0\x93\xdf\x02\x03\x01\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
PublicKey_MD5: b86c8d84e4cddad72f0a31454b020036
C2Server: d1rsx3ll433ur2.cloudfront.net,/s/ref=nb_sb_noss_1/167-3294888-026249/field-keywords=year
UserAgent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
HttpPostUri: /N4215/adj/amzn.us.sr.aps
Malleable_C2_Instructions: []
HttpGet_Metadata: {'ConstHeaders': ['Accept: */*', 'Host: d1rsx3ll433ur2.cloudfront.net'], 'ConstParams': [], 'Metadata': ['base64', 'prepend "session-token="', 'append "csm-hit=s-24KU11BB82RZSYGJ3BDK|1419899012996"', 'append "; skin=noskin"', 'header "Cookie"'], 'SessionId': [], 'Output': []}
HttpPost_Metadata: {'ConstHeaders': ['Accept: */*', 'Content-Type: text/xml', 'X-Requested-With: XMLHttpRequest', 'Host: d1rsx3ll433ur2.cloudfront.net'], 'ConstParams': ['sz=160x600', 'oe=oe=ISO-8859-1;', 's=3717', 'dc_ref=http%3A%2F%2Fwww.amazon.com'], 'Metadata': [], 'SessionId': ['parameter "sn"'], 'Output': ['base64', 'print']}
SpawnTo: b'%\x7f=J\x01\xce\xc5\x00\x0f4a\xcb}\xccp\x04'
PipeName: Not Found
DNS_Idle: Not Found
DNS_Sleep: Not Found
SSH_Host: Not Found
SSH_Port: Not Found
SSH_Username: Not Found
SSH_Password_Plaintext: Not Found
SSH_Password_Pubkey: Not Found
SSH_Banner:
HttpGet_Verb: GET
HttpPost_Verb: POST
HttpPostChunk: 0
Spawnto_x86: %windir%\syswow64\wermgr.exe
Spawnto_x64: %windir%\sysnative\wermgr.exe
CryptoScheme: 0
Proxy_Config: Not Found
Proxy_User: Not Found
Proxy_Password: Not Found
Proxy_Behavior: Use IE settings
Watermark: 1721689921
bStageCleanup: False
bCFGCaution: False
KillDate: 2022-03-01
bProcInject_StartRWX: True
bProcInject_UseRWX: True
bProcInject_MinAllocSize: 0
ProcInject_PrependAppend_x86: Empty
ProcInject_PrependAppend_x64: Empty
ProcInject_Execute: ['CreateThread', 'SetThreadContext', 'CreateRemoteThread', 'RtlCreateUserThread']
ProcInject_AllocationMethod: VirtualAllocEx
ProcInject_Stub: b'\x04\xe0\xa1\x1b\xe5\x91G\xa8\xd7=+>\x9f\xea\x83,'
bUsesCookies: True
HostHeader:
smbFrameHeader: b'\x00\x04\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
tcpFrameHeader: b'\x00\x04\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
headersToRemove: Not Found
DNS_Beaconing: Not Found
DNS_get_TypeA: Not Found
DNS_get_TypeAAAA: Not Found
DNS_get_TypeTXT: Not Found
DNS_put_metadata: Not Found
DNS_put_output: Not Found
DNS_resolver: Not Found
DNS_strategy: round-robin
DNS_strategy_rotate_seconds: -1
DNS_strategy_fail_x: -1
DNS_strategy_fail_seconds: -1