Cobalt Stike Beacon Detected – 172[.]105[.]81[.]87:443

Cobalt Strike Beacon Detection Alerts

The Information provided at the time of posting was detected as “Cobalt Strike”. Depending on when you are viewing this article, it may no longer be the case and could be determined as being a false positive. Please do your own additional validation. – RedPacket Security

TimeStamp 2021-11-13T13:04:02.843726

Cobalt Strike
Cobalt Strike

General Information

3.4770623095003373e+41
Cloud ProviderLinode
Cloud Regionde-he
ServiceN/A
Domainslinodeusercontent[.]com
Hostnames172-105-81-87[.]ip[.]linodeusercontent[.]com
HTTP Host172[.]105[.]81[.]87
ISPLinode, LLC
ORGLinode
OSN/A
HTTPN/A
HTTP HTML HASHN/A
HTTP LOCATION/
HTTP REDIRECTS
HTTP ROBOTSN/A
HTTP ROBOTS HASHN/A
HTTP SECURITY.TXTN/A
HTTP SECURITY.TXT HASHN/A
HTTP SERVERnginx
HTTP SITEMAPN/A
HTTP SITEMAP HASHN/A
HTTP TITLEN/A
LOCATION (AREA CODE)N/A
LOCATION (CITY)Frankfurt am Main
LOCATION (COUNTRY CODE)DE
LOCATION (COUNTRY NAME)Germany
LOCATION (LATITUDE)50.1025
LOCATION (LONGITUDE)8.6299
LOCATION (POSTAL CODE)N/A
SSL SERIAL
SSL EXPIREDN/A
SSL FINGERPRINT (SHA1)e9af07418ac41885fe9df746cf0b97f704325fb9
SSL ISSUED20211111151159Z
SSL EXPIRES20220209151158Z
SSL CYPHERECDHE-RSA-AES256-GCM-SHA384
SSL VERSIONTLSv1/SSLv3
SSL TRUST (REVOKED)N/A
TAGScloud


Cobalt Strike Beacon Information

Beacon TypeHTTPS
http-get.clientCookie
http-post.clientContent-Type: application/octet-stream, id
DNS Beacon MaxDNSN/A
DNS Beacon IdleN/A
Beacon Jitter33
dns-beacon.strategy_fail_seconds-1
dns-beacon.strategy_rotate_seconds-1
dns-beacon.strategy_fail_x-1
HTTP GET URIwww[.]stellesupport[.]com,/dot[.]gif
HTTP POST URI/submit.php
Max GET Size1048576
Port443
post-ex.spawnto_x64%windir%\sysnative\rundll32[.]exe
post-ex.spawnto_x86%windir%\syswow64\rundll32[.]exe
process-inject.startrwx64
process-inject.userwx64
process-inject.allocatorN/A
proxy.behavior2 (Use IE settings)
sleeptime37500
useragent_headerMozilla/5.0 (Windows NT 6.1) AppleWebKit/587.38 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36
uses_cookies1
process-inject.executeCreateThread, SetThreadContext, CreateRemoteThread, RtlCreateUserThread
Watermark48306859
Beacon Stage CleanupN/A