Skip to content

Instantly share code, notes, and snippets.

Show Gist options
  • Save MichaelKoczwara/8538ce4249f169563552e0b2be9728a1 to your computer and use it in GitHub Desktop.
Save MichaelKoczwara/8538ce4249f169563552e0b2be9728a1 to your computer and use it in GitHub Desktop.
Cobalt Strike/C2 218.132.147.207 - 18.130.120.177 c2: sage-salesforce.com/image
18.130.120.177
ec2-18-130-120-177.eu-west-2.compute.amazonaws.com
{"x64": {"md5": "2464855b99ecfd5a0700362a4e0d7656", "config": {"Method 1": "GET", "HTTP Method Path 2": "\/history\/", "Jitter": 0, "C2 Server": "sage-salesforce.com,\/image\/", "Polling": 5000, "Spawn To x86": "%windir%\\syswow64\\mstsc.exe", "Method 2": "GET", "Port": 443, "Beacon Type": "8 (HTTPS)", "Spawn To x64": "%windir%\\sysnative\\mstsc.exe"}, "sha256": "2d1082f1d75d8dc7e66268cf0611d3154d4fe9c43164386d15f64338328b3ccd", "sha1": "be3c6cab9996eee75b08b1d642bef033fee13b58", "time": 1618653337245.6}, "x86": {"md5": "7ffdc76fae6f5b9e2368aa9f6e91eb43", "config": {"Method 1": "GET", "HTTP Method Path 2": "\/history\/", "Jitter": 0, "C2 Server": "sage-salesforce.com,\/image\/", "Polling": 5000, "Spawn To x86": "%windir%\\syswow64\\mstsc.exe", "Method 2": "GET", "Port": 443, "Beacon Type": "8 (HTTPS)", "Spawn To x64": "%windir%\\sysnative\\mstsc.exe"}, "sha256": "ea8bbe9060f7c0e05a1efc648d72753a62e7ecbef1d8ad239c2ba83d43cd10fc", "sha1": "630d4014ce36ea546447e7d116c0c51b894ae147", "time": 1618653335657.3}}
18.132.147.207
ec2-18-132-147-207.eu-west-2.compute.amazonaws.com
{"x64": {"sha256": "2d1082f1d75d8dc7e66268cf0611d3154d4fe9c43164386d15f64338328b3ccd", "md5": "2464855b99ecfd5a0700362a4e0d7656", "time": 1618652826183.6, "sha1": "be3c6cab9996eee75b08b1d642bef033fee13b58", "config": {"Jitter": 0, "Spawn To x64": "%windir%\\sysnative\\mstsc.exe", "Polling": 5000, "C2 Server": "sage-salesforce.com,\/image\/", "Method 1": "GET", "Spawn To x86": "%windir%\\syswow64\\mstsc.exe", "Beacon Type": "8 (HTTPS)", "HTTP Method Path 2": "\/history\/", "Port": 443, "Method 2": "GET"}}, "x86": {"sha256": "ea8bbe9060f7c0e05a1efc648d72753a62e7ecbef1d8ad239c2ba83d43cd10fc", "md5": "7ffdc76fae6f5b9e2368aa9f6e91eb43", "time": 1618652824604.3, "sha1": "630d4014ce36ea546447e7d116c0c51b894ae147", "config": {"Jitter": 0, "Spawn To x64": "%windir%\\sysnative\\mstsc.exe", "Polling": 5000, "C2 Server": "sage-salesforce.com,\/image\/", "Method 1": "GET", "Spawn To x86": "%windir%\\syswow64\\mstsc.exe", "Beacon Type": "8 (HTTPS)", "HTTP Method Path 2": "\/history\/", "Port": 443, "Method 2": "GET"}}}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment