Cobalt Stike Beacon Detected – 113[.]23[.]144[.]117:443

Cobalt Strike Beacon Detection Alerts

The Information provided at the time of posting was detected as “Cobalt Strike”. Depending on when you are viewing this article, it may no longer be the case and could be determined as being a false positive. Please do your own additional validation. – RedPacket Security

TimeStamp 2021-11-12T11:53:19.164796

Cobalt Strike
Cobalt Strike

General Information

3.2453649048649985e+47
Cloud Provider
Cloud Region
Service
Domainscouipseley[.]com
Hostnamesvrir[.]couipseley[.]com
HTTP Host113[.]23[.]144[.]117
ISPExtreme Broadband – Total Broadband Experience
ORGExtreme Broadband Sdn. Bhd.,
OSN/A
HTTPN/A
HTTP HTML HASHN/A
HTTP LOCATION/
HTTP REDIRECTS
HTTP ROBOTSN/A
HTTP ROBOTS HASHN/A
HTTP SECURITY.TXTN/A
HTTP SECURITY.TXT HASHN/A
HTTP SERVERN/A
HTTP SITEMAPN/A
HTTP SITEMAP HASHN/A
HTTP TITLEN/A
LOCATION (AREA CODE)N/A
LOCATION (CITY)Kuala Lumpur
LOCATION (COUNTRY CODE)MY
LOCATION (COUNTRY NAME)Malaysia
LOCATION (LATITUDE)3.1412
LOCATION (LONGITUDE)101.68653
LOCATION (POSTAL CODE)N/A
SSL SERIAL
SSL EXPIREDN/A
SSL FINGERPRINT (SHA1)ff396a843dbfc6bb2929c33137c9ec1bc5b187e8
SSL ISSUED20210908012900Z
SSL EXPIRES20230908012900Z
SSL CYPHERECDHE-RSA-AES256-GCM-SHA384
SSL VERSIONTLSv1/SSLv3
SSL TRUST (REVOKED)N/A
TAGS


Cobalt Strike Beacon Information

Beacon TypeHTTPS
http-get.clientHost: www[.]dellinspiration[.]com, Accept: */*, Accept-Language: en-US,en;q=0[.]5, Connection: close, _SS=, SRCHD=AF=NOFORM;, Cookie, q=san%20diego%20ca%20zoo
http-post.clientHost: www[.]dellinspiration[.]com, Accept: */*, Accept-Language: en-US, Content-Type: text/xml, Connection: close, SRCHUID=, SRCHD=AF=NOFORM;, Cookie, lid
DNS Beacon MaxDNS245
DNS Beacon Idle134744072
Beacon Jitter27
dns-beacon.strategy_fail_secondsN/A
dns-beacon.strategy_rotate_secondsN/A
dns-beacon.strategy_fail_xN/A
HTTP GET URIwww[.]dellinspiration[.]com,/maps/overlaybfpr
HTTP POST URI/fd/ls/lsp.aspx
Max GET Size1400793
Port443
post-ex.spawnto_x64%windir%\sysnative\gpupdate[.]exe
post-ex.spawnto_x86%windir%\syswow64\gpupdate[.]exe
process-inject.startrwx64
process-inject.userwx32
process-inject.allocator1
proxy.behavior2 (Use IE settings)
sleeptime38500
useragent_headerMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
uses_cookies1
process-inject.executentdll.dll:RtlUserThreadStart, SetThreadContext, NtQueueApcThread-s, kernel32.dll:LoadLibraryA, RtlCreateUserThread
Watermark305419896
Beacon Stage Cleanup1