Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2020-12-15 (TUESDAY) COBALT STRIKE (BEACON) TRAFFIC ASSOCIATED WITH QAKBOT (QBOT) INFECTION:
- REFERENCES:
- - https://www.malware-traffic-analysis.net/2020/12/15/index.html
- - https://twitter.com/malware_traffic/status/1339647762934194178
- TRAFFIC:
- - 172.241.27[.]244 port 443 - matesmapizza[.]com - HTTPS traffic
- - 172.241.27[.]244 port 80 - matesmapizza[.]com - GET /ga.js
- - 172.241.27[.]244 port 80 - matesmapizza[.]com - GET /updates.rss
- - 172.241.27[.]244 port 8888 - matesmapizza[.]com:8888 - GET /pixel
- - 172.241.27[.]244 port 80 - matesmapizza[.]com - POST /submit.php?id=[9-digit number]
- - 172.241.27[.]244 port 8888 - matesmapizza[.]com:8888 - POST /submit.php?id=[9-digit number]
- - 185.125.206[.]173 port 8080 - travmeetlett[.]com - HTTPS traffic
- - 185.125.206[.]173 port 443 - travmeetlett[.]com:443 - GET /match
- - 185.125.206[.]173 port 443 - travmeetlett[.]com:443 - GET /dpixel
RAW Paste Data