Skip to content

Instantly share code, notes, and snippets.

@MichaelKoczwara
Created September 13, 2021 08:47
Show Gist options
  • Save MichaelKoczwara/17768172dc2d319c2ccf2c3dea796ada to your computer and use it in GitHub Desktop.
Save MichaelKoczwara/17768172dc2d319c2ccf2c3dea796ada to your computer and use it in GitHub Desktop.
Cobalt Strike C2 possibly linked to CVE-2021-40444 hosted on combahton.net
ip:
45.147.230.87
45.147.230.236
45.153.241.251
45.153.242.111
45.147.228.115
45.147.228.143
45.153.242.112
152.89.247.172
45.138.172.37
152.89.247.37
domains:
nagiwo.com/ny
howeyoh.com/ky
rurofo.com,/en.js
luherih.com/lt
viwiba.com/groupcp.html
viwiba.com/panel.html
yizabu.com/RELEASES.html
bupula.com/RELEASES.html
zosohev.com/cr
fonazax.com/kj
rasokuc.com/bn.js
waceko.com/FAQ.html
pobosa.com/mk.js
racijo.com/mk.js
Watermarks 1580103814 and 0
---------------------------------------
Cobalt Strike Watermark: 0
45.147.230.87
HTTP/1.1 404 Not Found
Server: Microsoft-IIS/8.5
Content-Type: text/plain
Cache-Control: max-age=1
Connection: keep-alive
X-Powered-By: ASP.NET
Content-Length: 0
CobaltStrike Beacon configurations:
| x86 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 10
| C2 Server: nagiwo.com,/ny,howeyoh.com,/ky
| HTTP Method Path 2: /ny
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\rundll32.exe
| Spawnto_x64: %windir%\sysnative\rundll32.exe
| Proxy_AccessType: 2 (Use IE settings)
|
|
| x64 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 10
| C2 Server: nagiwo.com,/ny,howeyoh.com,/ky
| HTTP Method Path 2: /ny
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\rundll32.exe
| Spawnto_x64: %windir%\sysnative\rundll32.exe
| Proxy_AccessType: 2 (Use IE settings)
|_
------------------------------------------------
Cobalt Strike Watermark: 0
45.147.230.236
HTTP/1.1 404 Not Found
Server: Microsoft-IIS/8.5
Content-Type: text/plain
Cache-Control: max-age=1
Connection: keep-alive
X-Powered-By: ASP.NET
Content-Length: 0
CobaltStrike Beacon configurations:
| x86 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 43
| C2 Server: rurofo.com,/en.js
| HTTP Method Path 2: /tab_shop
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\wusa.exe
| Spawnto_x64: %windir%\sysnative\wusa.exe
| Proxy_AccessType: 2 (Use IE settings)
|
|
| x64 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 43
| C2 Server: rurofo.com,/en.js
| HTTP Method Path 2: /mobile-android
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\wusa.exe
| Spawnto_x64: %windir%\sysnative\wusa.exe
| Proxy_AccessType: 2 (Use IE settings)
|_
----------------------------------------------
45.153.241.251
HTTP/1.1 404 Not Found
Server: Microsoft-IIS/8.5
Content-Type: text/plain
Cache-Control: max-age=1
Connection: keep-alive
X-Powered-By: ASP.NET
Content-Length: 0
CobaltStrike Beacon configurations:
| x86 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 33
| C2 Server: luherih.com,/lt
| HTTP Method Path 2: /favicon
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\wusa.exe
| Spawnto_x64: %windir%\sysnative\wusa.exe
| Proxy_AccessType: 2 (Use IE settings)
|
|
| x64 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 33
| C2 Server: luherih.com,/lt
| HTTP Method Path 2: /br
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\wusa.exe
| Spawnto_x64: %windir%\sysnative\wusa.exe
| Proxy_AccessType: 2 (Use IE settings)
|_
---------------------------------------------
Cobalt Strike Watermark: 1580103814
45.153.242.111
HTTP/1.1 404 Not Found
Server: Microsoft-IIS/8.5
Content-Type: text/plain
Cache-Control: max-age=1
Connection: keep-alive
X-Powered-By: ASP.NET
Content-Length: 0
CobaltStrike Beacon configurations:
| x86 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 33
| C2 Server: viwiba.com,/groupcp.html
| HTTP Method Path 2: /nd
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\mstsc.exe
| Spawnto_x64: %windir%\sysnative\mstsc.exe
| Proxy_AccessType: 2 (Use IE settings)
|
|
| x64 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 33
| C2 Server: viwiba.com,/panel.html
| HTTP Method Path 2: /af
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\mstsc.exe
| Spawnto_x64: %windir%\sysnative\mstsc.exe
| Proxy_AccessType: 2 (Use IE settings)
|_
-----------------------------------------------
Cobalt Strike Watermark: 1580103814
45.147.228.115
HTTP/1.1 404 Not Found
Server: Microsoft-IIS/8.5
Content-Type: text/plain
Cache-Control: max-age=1
Connection: keep-alive
X-Powered-By: ASP.NET
Content-Length: 0
CobaltStrike Beacon configurations:
| x86 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 9
| C2 Server: yizabu.com,/RELEASES.html,bupula.com,/RELEASES.html
| HTTP Method Path 2: /cs
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\rundll32.exe
| Spawnto_x64: %windir%\sysnative\rundll32.exe
| Proxy_AccessType: 2 (Use IE settings)
|
|
| x64 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 9
| C2 Server: yizabu.com,/RELEASES.html,bupula.com,/RELEASES.html
| HTTP Method Path 2: /cs
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\rundll32.exe
| Spawnto_x64: %windir%\sysnative\rundll32.exe
| Proxy_AccessType: 2 (Use IE settings)
|_
------------------------------------------------------------------
Cobalt Strike Watermark: 0
45.147.228.143
HTTP/1.1 404 Not Found
Server: Microsoft-IIS/8.5
Content-Type: text/plain
Cache-Control: max-age=1
Connection: keep-alive
X-Powered-By: ASP.NET
Content-Length: 0
CobaltStrike Beacon configurations:
| x86 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 18
| C2 Server: zosohev.com,/cr
| HTTP Method Path 2: /lt
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\wusa.exe
| Spawnto_x64: %windir%\sysnative\wusa.exe
| Proxy_AccessType: 2 (Use IE settings)
|
|
| x64 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 18
| C2 Server: zosohev.com,/cr
| HTTP Method Path 2: /en
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\wusa.exe
| Spawnto_x64: %windir%\sysnative\wusa.exe
| Proxy_AccessType: 2 (Use IE settings)
|_
---------------------------------------------
Cobalt Strike Watermark: 1580103814
45.153.242.112
HTTP/1.1 404 Not Found
Server: Microsoft-IIS/8.5
Content-Type: text/plain
Cache-Control: max-age=1
Connection: keep-alive
X-Powered-By: ASP.NET
Content-Length: 0
CobaltStrike Beacon configurations:
| x86 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 37
| C2 Server: 23.92.210.210,/tab_shop_active
| HTTP Method Path 2: /tab_shop_active
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\mstsc.exe
| Spawnto_x64: %windir%\sysnative\mstsc.exe
| Proxy_AccessType: 2 (Use IE settings)
|
|
| x64 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 37
| C2 Server: 23.92.210.210,/ce
| HTTP Method Path 2: /tab_shop_active
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\mstsc.exe
| Spawnto_x64: %windir%\sysnative\mstsc.exe
| Proxy_AccessType: 2 (Use IE settings)
|_
------------------------------------------------
Cobalt Strike Watermark: 1580103814
152.89.247.172
HTTP/1.1 404 Not Found
X-Powered-By: ASP.NET
Content-Length: 0
Server: Microsoft-IIS/8.5
Content-Type: text/plain
Cache-Control: max-age=1
Connection: keep-alive
CobaltStrike Beacon configurations:
| x86 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 31
| C2 Server: fonazax.com,/kj
| HTTP Method Path 2: /faq
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\wusa.exe
| Spawnto_x64: %windir%\sysnative\wusa.exe
| Proxy_AccessType: 2 (Use IE settings)
|
|
| x64 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 31
| C2 Server: fonazax.com,/kj
| HTTP Method Path 2: /faq
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\wusa.exe
| Spawnto_x64: %windir%\sysnative\wusa.exe
| Proxy_AccessType: 2 (Use IE settings)
|_
---------------------------------------------
45.138.172.37
HTTP/1.1 404 Not Found
X-Powered-By: ASP.NET
Content-Length: 0
Server: Microsoft-IIS/8.5
Content-Type: text/plain
Cache-Control: max-age=1
Connection: keep-alive
CobaltStrike Beacon configurations:
| x86 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 28
| C2 Server: rasokuc.com,/bn.js
| HTTP Method Path 2: /common
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\wusa.exe
| Spawnto_x64: %windir%\sysnative\wusa.exe
| Proxy_AccessType: 2 (Use IE settings)
|
|
| x64 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 28
| C2 Server: rasokuc.com,/bn.js
| HTTP Method Path 2: /na
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\wusa.exe
| Spawnto_x64: %windir%\sysnative\wusa.exe
| Proxy_AccessType: 2 (Use IE settings)
|_
----------------------------------------------
45.147.231.12
HTTP/1.1 404 Not Found
Cache-Control: max-age=1
Connection: keep-alive
X-Powered-By: ASP.NET
Content-Length: 0
Server: Microsoft-IIS/8.5
Content-Type: text/plain
CobaltStrike Beacon configurations:
| x86 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 4
| C2 Server: waceko.com,/FAQ.html
| HTTP Method Path 2: /na
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\wusa.exe
| Spawnto_x64: %windir%\sysnative\wusa.exe
| Proxy_AccessType: 2 (Use IE settings)
|
|
| x64 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 4
| C2 Server: waceko.com,/FAQ.html
| HTTP Method Path 2: /na
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\wusa.exe
| Spawnto_x64: %windir%\sysnative\wusa.exe
| Proxy_AccessType: 2 (Use IE settings)
|_
----------------------------------------------
152.89.247.37
HTTP/1.1 404 Not Found
Connection: keep-alive
X-Powered-By: ASP.NET
Content-Length: 0
Server: Microsoft-IIS/8.5
Content-Type: text/plain
Cache-Control: max-age=1
CobaltStrike Beacon configurations:
| x86 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 28
| C2 Server: pobosa.com,/mk.js,racijo.com,/mk.js
| HTTP Method Path 2: /extension
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\rundll32.exe
| Spawnto_x64: %windir%\sysnative\rundll32.exe
| Proxy_AccessType: 2 (Use IE settings)
|
|
| x64 URI Response:
| BeaconType: 8 (HTTPS)
| Port: 443
| Polling: 5000
| Jitter: 28
| C2 Server: pobosa.com,/mk.js,racijo.com,/mk.js
| HTTP Method Path 2: /ce
| Method1: GET
| Method2: POST
| Spawnto_x86: %windir%\syswow64\rundll32.exe
| Spawnto_x64: %windir%\sysnative\rundll32.exe
| Proxy_AccessType: 2 (Use IE settings)
|_
------------------------------------------------------
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment