Skip to content

Instantly share code, notes, and snippets.

Show Gist options
  • Save MichaelKoczwara/eab6a3cba534262b1566af367b21b559 to your computer and use it in GitHub Desktop.
Save MichaelKoczwara/eab6a3cba534262b1566af367b21b559 to your computer and use it in GitHub Desktop.
Cobalt Strike servers 23.248.248.2 -23.248.248.6
Cobalt Strike servers
All hosted on Xiaozhiyun L.L.C
-----------------
c2
23.248.248.6/j.ad
------------------
23.248.248.2
23.248.248.3
23.248.248.4
23.248.248.5
23.248.248.6
---------------
beacon sample
{"x64": {"time": 1617568932238.0, "md5": "13f0f318b9a15e76af8d71c0e0bee509", "sha1": "40fefeb515b40ef4c0cdebc381b27528685022ed", "sha256": "5584d814131fcf46673f6f780d6cd0dbc93c7469fa736032285ca9d222a1dff4", "config": {"Method 1": "GET", "Polling": 60000, "Jitter": 0, "HTTP Method Path 2": "\/submit.php", "Port": 8080, "Spawn To x86": "%windir%\\syswow64\\rundll32.exe", "Method 2": "POST", "Beacon Type": "0 (HTTP)", "Spawn To x64": "%windir%\\sysnative\\rundll32.exe", "C2 Server": "23.248.248.6,\/j.ad"}}, "x86": {"time": 1617568928989.4, "md5": "f7412402ff926bff5b86ed1d6c562006", "sha1": "0c5a8d1ab8722d142974000262a30b881f213e07", "sha256": "465e214a75340fa74014f8b29a4aa74f832b3ccb29fe1d3383ba2bd6b16c7c43", "config": {"Method 1": "GET", "Polling": 60000, "Jitter": 0, "HTTP Method Path 2": "\/submit.php", "Port": 8080, "Spawn To x86": "%windir%\\syswow64\\rundll32.exe", "Method 2": "POST", "Beacon Type": "0 (HTTP)", "Spawn To x64": "%windir%\\sysnative\\rundll32.exe", "C2 Server": "23.248.248.6,\/ptj"}}}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment