Advertisement
Bank_Security

Cobalt APT IOCs

Aug 2nd, 2019
15,821
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.71 KB | None | 0 0
  1. Appendix A: IOCs
  2.  
  3. https://kassanova[.]kz/files/docs/T47188445.doc – Malicious document drop-zone
  4.  
  5. 7f0f3689b728d12a00ca258c688bf034 – MD5: Malicious document
  6.  
  7. a26722fc7e5882b5a273239cddfe755f – MD5: Downloaded Payload
  8.  
  9. 185.61.149[.]186 – Cobalt Strike beacon C2
  10.  
  11.  
  12.  
  13. Appendix B: Cobalt beacon configuration
  14.  
  15. {
  16. 'PROTOCOL': '0',
  17. 'SPAWNTO_X64':'%windir%\\sysnative\\gpupdate.exe',
  18. 'SLEEPTIME': '30000',
  19. 'C2_VERB_GET': 'GET',
  20. 'DNS_SLEEP': '0',
  21. 'MAXGET': '1398102',
  22. 'USERAGENT': 'Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko)', 'PORT': '80',
  23. 'DNS_IDLE': '134744072',
  24. 'C2_POSTREQ': "[('_HEADER', 0, 'Accept: */*'), ('BUILD', ('BASE64URL',)), ('PREPEND', 0, 'wla42='), ('PREPEND', 0, 'xid=730bf7;'), ('PREPEND', 0, 'MSPAuth=3EkAjDKjI;'), ('PREPEND', 0, 'ClientId=1C0F6C5D910F9;'), ('PREPEND', 0, 'MicrosoftApplicationsTelemetryDeviceId=95c18d8-4dce9854;'), ('HEADER', 0, 'Cookie')]",
  25. 'WATERMARK': '3',
  26. 'PUBKEY': '30819f300d06092a864886f70d010101050003818d00308189028181008f8c237f7f407fcf5f47e2d76c589982b2595ead0d45d4e4ea875b2d07f2b8283f64786c7a142d3ce78baa01d1bb14479162d14520cc8ba15b1dc0b5e57850ab7bccb95838156dec5b58097a007d0180e358e144653d80381ac240efe9b789adf5f319515651bdfc3eb160b411f5cba2b8e7e21cb2cbc743b5ffb6fba5d2b8ff0203010001',
  27. 'SPAWNTO_X86': '%windir%\\syswow64\\gpupdate.exe',
  28. 'C2_REQUEST': "[('_HEADER', 0, 'Accept: */*'), ('_HEADER', 0, 'Cookie: MicrosoftApplicationsTelemetryDeviceId=95c18d8-4dce9854;ClientId=1C0F6C5D910F9;MSPAuth=3EkAjDKjI;xid=730bf7;wla42=ZG0yMzA2KjEs'), ('BUILD', ('BASE64URL',))]",
  29. 'CRYPTO_SCHEME': '0',
  30. 'JITTER': '20',
  31. 'C2_CHUNK_POST':'96',
  32. 'PIPENAME': '',
  33. 'C2_VERB_POST': 'GET',
  34. 'SUBMITURI': '/OWA/',
  35. 'DOMAINS': '185.61.149.186,/owa/',
  36. 'MAXDNS': '235'
  37. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement