ThreatFox IOC Database
You are viewing the ThreatFox database entry for url https://d3cx8c9rmhubj4.cloudfront.net:443/s/ref=nb_sb_noss_1/167-3294888-026249/field-keywords=year.
Database Entry
This IOC expired
This IOC is an old IOC and hence has expired on 2026-09-11 01:15:01 UTC. We therefore refrain from exporting it into our datasets. As a result, this database entry is purely informational and has no impact.
| IOC ID: | 306032 |
|---|---|
| IOC: | https://d3cx8c9rmhubj4.cloudfront.net:443/s/ref=nb_sb_noss_1/167-3294888-026249/field-keywords=year |
| IOC Type : | url |
| Threat Type : | botnet_cc |
| Malware: | Cobalt Strike |
| Malware alias: | Agentemis, BEACON, CobaltStrike, cobeacon |
| Confidence Level : | Confidence level is moderate (50%) |
| Is compromised? : | False |
| First seen: | 2022-01-20 08:00:02 UTC |
| Last seen: | never |
| UUID: | f8b4dad2-79c6-11ec-8ab6-42010aa4000a |
| Reporter | |
| Reward | 5 credits from ThreatFox |
| Tags: | CobaltStrike |
NexusFuzzy
[ Download URL of Beacon ]https://35.174.35.184:443/
[ Extracted Beacon Config ]
BeaconType: ['HTTPS']
Port: 443
SleepTime: 5000
MaxGetSize: 1048576
Jitter: 0
MaxDNS: Not Found
PublicKey: b'0\x81\x9f0\r\x06\t*\x86H\x86\xf7\r\x01\x01\x01\x05\x00\x03\x81\x8d\x000\x81\x89\x02\x81\x81\x00\xc9\x82p\x04d\x05]4A\x02\xd5[\x97Z2\x1d\xed\xf1t\xcf\xbbo\xae\xd93~\xc0{z{\xe0\xb3@\x1d2\xf2\xcf\xb0\xe4\xe3\xcc\x9fb\xddB\xfc1_-\xf9O\xcd\x9b\xbd\x91\xb3\x1d8e\xb6\x05R\xcb\xaf\xcc\x87>YG\x9c\xaf#\xd7Da\x8a\xcb@\xc1L\xf6\xd2{\xd4T\x11c\xf1\x9a\r\x133\xe3\x99\xebP{r\x8er\xe9\n.\x1f\xc6\x00( 7\xc9\x03\xe3\xb1\x85\x90G\xf3X\xa1\xaco\xde\x80\x9d)\xfa\xc4\xe1\x02\x03\x01\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
PublicKey_MD5: ceafc0d4cbdd1d64dec54b84194e7f39
C2Server: d3cx8c9rmhubj4.cloudfront.net,/s/ref=nb_sb_noss_1/167-3294888-026249/field-keywords=year
UserAgent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
HttpPostUri: /N4215/adj/amzn.us.sr.aps
Malleable_C2_Instructions: []
HttpGet_Metadata: {'ConstHeaders': ['Accept: */*', 'Host: d3cx8c9rmhubj4.cloudfront.net'], 'ConstParams': [], 'Metadata': ['base64', 'prepend "session-token="', 'append "csm-hit=s-24KU11BB82RZSYGJ3BDK|1419899012996"', 'append "; skin=noskin"', 'header "Cookie"'], 'SessionId': [], 'Output': []}
HttpPost_Metadata: {'ConstHeaders': ['Accept: */*', 'Content-Type: text/xml', 'X-Requested-With: XMLHttpRequest', 'Host: d3cx8c9rmhubj4.cloudfront.net'], 'ConstParams': ['sz=160x600', 'oe=oe=ISO-8859-1;', 's=3717', 'dc_ref=http%3A%2F%2Fwww.amazon.com'], 'Metadata': [], 'SessionId': ['parameter "sn"'], 'Output': ['base64', 'print']}
SpawnTo: b"G\xddt_\x91^?\xce\x00F\x0f\xcc\xc9e'\xe2"
PipeName: Not Found
DNS_Idle: Not Found
DNS_Sleep: Not Found
SSH_Host: Not Found
SSH_Port: Not Found
SSH_Username: Not Found
SSH_Password_Plaintext: Not Found
SSH_Password_Pubkey: Not Found
SSH_Banner:
HttpGet_Verb: GET
HttpPost_Verb: POST
HttpPostChunk: 0
Spawnto_x86: %windir%\syswow64\wermgr.exe
Spawnto_x64: %windir%\sysnative\wermgr.exe
CryptoScheme: 0
Proxy_Config: Not Found
Proxy_User: Not Found
Proxy_Password: Not Found
Proxy_Behavior: Use IE settings
Watermark: 1083092832
bStageCleanup: False
bCFGCaution: False
KillDate: 2022-01-29
bProcInject_StartRWX: True
bProcInject_UseRWX: True
bProcInject_MinAllocSize: 0
ProcInject_PrependAppend_x86: Empty
ProcInject_PrependAppend_x64: Empty
ProcInject_Execute: ['CreateThread', 'SetThreadContext', 'CreateRemoteThread', 'RtlCreateUserThread']
ProcInject_AllocationMethod: VirtualAllocEx
ProcInject_Stub: b'"+\x8f\'\xdb\xdf\xba\x8d\xddU\x9e\xec\xa2~\xa6H'
bUsesCookies: True
HostHeader:
smbFrameHeader: b'\x00\x04\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
tcpFrameHeader: b'\x00\x04\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
headersToRemove: Not Found
DNS_Beaconing: Not Found
DNS_get_TypeA: Not Found
DNS_get_TypeAAAA: Not Found
DNS_get_TypeTXT: Not Found
DNS_put_metadata: Not Found
DNS_put_output: Not Found
DNS_resolver: Not Found
DNS_strategy: round-robin
DNS_strategy_rotate_seconds: -1
DNS_strategy_fail_x: -1
DNS_strategy_fail_seconds: -1