Skip to content

Instantly share code, notes, and snippets.

@MichaelKoczwara
Created September 19, 2021 16:09
Show Gist options
  • Save MichaelKoczwara/f1038d0625d8472a7264b0fd18cbed88 to your computer and use it in GitHub Desktop.
Save MichaelKoczwara/f1038d0625d8472a7264b0fd18cbed88 to your computer and use it in GitHub Desktop.
209.249.134.12
{"x64": {"time": 1632046026055.9,
"sha1": "62862d22134c8b566d74e753f0215007ee95a8d1",
"sha256": "17eac46860fe0c853b245dd997eb45721073a0a2475249a6a2ae33d7e8a98cd4",
"config": {"HTTP Method Path 2": "\/api\/conversations.create",
"Polling": 30000,
"Watermark": 1192230662,
"Spawn To x86": "C:\\windows\\system32\\conhost.exe 0x4",
"Port": 443, "Beacon Type": "8 (HTTPS)",
"C2 Server": "www.davismemorialhospital.org,\/api\/channels\/replies",
"C2 Host Header": "Host: www.davismemorialhospital.org\r\n",
"Jitter": 80, "Method 2": "POST",
"Method 1": "GET",
"Spawn To x64": "C:\\windows\\system32\\conhost.exe 0x4"},
"md5": "f4a1e1af7ae77a6fe33989b6ae123116",
"uri_queried": "\/sABg"},
"x86": {"time": 1632046023897.4,
"sha1": "dbdc0984c16df1a462c250942c4e2cbbc327233e",
"sha256": "3031f2e023bb628b334f09ff1902ebedeb36ce8e0410a32926f737a016e9a0b7",
"config": {"HTTP Method Path 2": "\/auth\/twofactor\/authenticator",
"Polling": 30000,
"Watermark": 1192230662,
"Spawn To x86": "C:\\windows\\system32\\conhost.exe 0x4",
"Port": 443, "Beacon Type": "8 (HTTPS)",
"C2 Server": "www.davismemorialhospital.org,\/user\/profile",
"C2 Host Header": "Host: www.davismemorialhospital.org\r\n",
"Jitter": 80, "Method 2": "POST",
"Method 1": "GET",
"Spawn To x64": "C:\\windows\\system32\\conhost.exe 0x4"},
"md5": "4b3987daedb73428ca6827e0ac735901",
"uri_queried": "\/LdCi"}}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment