Advertisement
ExecuteMalware

2021-03-12 Cobalt Strike Stager IOCS

Mar 12th, 2021
5,958
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.87 KB | None | 0 0
  1. THREAT IDENTIFICATION: COBALT STRIKE STAGER
  2.  
  3. SUBJECTS OBSERVED
  4. Case Notices for: 09-19-94883-CV
  5.  
  6. SENDERS OBSERVED
  7. Laura Williams <lrandolph@ocabcaa.org>
  8.  
  9. MALDOC FILE HASHES
  10. case#_1085423526_2097196119.xls
  11. 8f083b2940815cc411bd5305f949765b
  12.  
  13. COBALT STRIKE STAGER PAYLOAD URLS
  14. http://digitaldays.ro/site/brandupi.php
  15.  
  16. COBALT STRIKE STAGER FILE HASHES
  17. svh.osts
  18. 71032e98341065c93f38a226de74d7a0
  19.  
  20. ADDITIONAL FILE HASHES
  21. opa12.dat
  22. b1aff3b5ea271b3a0294d12257f2435a
  23.  
  24. COBALT STRIKE C2s
  25. https://onealabamasport.com/jquery-3.3.2.slim.min.js
  26. https://onealabamasport.com/jquery-3.3.1.min.js
  27.  
  28. SUPPORTING EVIDENCE
  29. https://urlhaus.abuse.ch/url/1063587/
  30. https://bazaar.abuse.ch/sample/b7d4f66a98e928dfb18d41021e5ad11043a3fc473c794edf481e8aa8c7cc9255/
  31. https://bazaar.abuse.ch/sample/132bdcb986e3e3b9599b5b293b3318e7c630495e87a9d1fa02287ae80f9e652f
  32. https://tria.ge/210312-wvcgbytymn
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement