Skip to content

Instantly share code, notes, and snippets.

Show Gist options
  • Save MichaelKoczwara/4feeb72a7dcf3d458612ee10c54660d5 to your computer and use it in GitHub Desktop.
Save MichaelKoczwara/4feeb72a7dcf3d458612ee10c54660d5 to your computer and use it in GitHub Desktop.
Cobalt Strike servers 23.226.51.96 - 23.226.51.126
Cobalt Strike servers
--------------------
beacon sample
{"x86": {"md5": "f7412402ff926bff5b86ed1d6c562006", "sha1": "0c5a8d1ab8722d142974000262a30b881f213e07", "time": 1617568268682.4, "config": {"Spawn To x64": "%windir%\\sysnative\\rundll32.exe", "Port": 8080, "Jitter": 0, "Polling": 60000, "Method 1": "GET", "Spawn To x86": "%windir%\\syswow64\\rundll32.exe", "Method 2": "POST", "HTTP Method Path 2": "\/submit.php", "C2 Server": "23.248.248.6,\/ptj", "Beacon Type": "0 (HTTP)"}, "sha256": "465e214a75340fa74014f8b29a4aa74f832b3ccb29fe1d3383ba2bd6b16c7c43"}, "x64": {"md5": "13f0f318b9a15e76af8d71c0e0bee509", "sha1": "40fefeb515b40ef4c0cdebc381b27528685022ed", "time": 1617568272135.7, "config": {"Spawn To x64": "%windir%\\sysnative\\rundll32.exe", "Port": 8080, "Jitter": 0, "Polling": 60000, "Method 1": "GET", "Spawn To x86": "%windir%\\syswow64\\rundll32.exe", "Method 2": "POST", "HTTP Method Path 2": "\/submit.php", "C2 Server": "23.248.248.6,\/j.ad", "Beacon Type": "0 (HTTP)"}, "sha256": "5584d814131fcf46673f6f780d6cd0dbc93c7469fa736032285ca9d222a1dff4"}}
------------------
C2
23.248.248.6/j.ad
------------------
All hosted on Xiaozhiyun L.L.C
-----------------
23.226.51.97
23.226.51.98
23.226.51.99
23.226.51.100
23.226.51.101
23.226.51.102
23.226.51.103
23.226.51.104
23.226.51.106
23.226.51.107
23.226.51.108
23.226.51.109
23.226.51.110
23.226.51.111
23.226.51.112
23.226.51.113
23.226.51.114
23.226.51.115
23.226.51.116
23.226.51.117
23.226.51.118
23.226.51.119
23.226.51.120
23.226.51.121
23.226.51.122
23.226.51.123
23.226.51.124
23.226.51.125
23.226.51.126
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment