General

  • Target

    280635176837a481603e19b0ec3b714ca692503bba45beff02a99f52a79d34dc

  • Size

    31KB

  • Sample

    250518-n85qqsdk2t

  • MD5

    d6608289695fe7ee74deb9906dafa150

  • SHA1

    53fe6edcf978642bf53c015f054edf5122473cb0

  • SHA256

    280635176837a481603e19b0ec3b714ca692503bba45beff02a99f52a79d34dc

  • SHA512

    f00fdb539e8b897941fc718187814cd6e822666efd38510f94c33e37b44c2e5e58cce8e33045a4bbbfd88ed59984e33a3788869cf509abbc804d16322cb837b5

  • SSDEEP

    384:OKLHk8/NdI2KVUh8Vq39T3hYscFaO52OmxSDsNE2KZt9y+/F:TLC2KV5q/YLaO56s

Malware Config

Extracted

Family

cobaltstrike

C2

http://47.122.115.29:443/kunkun/jquery-3.3.2.slim.min.js

Attributes
  • user_agent

    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Referer: http://www.baidu.com/ Accept-Encoding: gzip, deflate User-Agent: Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko

Targets

    • Target

      280635176837a481603e19b0ec3b714ca692503bba45beff02a99f52a79d34dc

    • Size

      31KB

    • MD5

      d6608289695fe7ee74deb9906dafa150

    • SHA1

      53fe6edcf978642bf53c015f054edf5122473cb0

    • SHA256

      280635176837a481603e19b0ec3b714ca692503bba45beff02a99f52a79d34dc

    • SHA512

      f00fdb539e8b897941fc718187814cd6e822666efd38510f94c33e37b44c2e5e58cce8e33045a4bbbfd88ed59984e33a3788869cf509abbc804d16322cb837b5

    • SSDEEP

      384:OKLHk8/NdI2KVUh8Vq39T3hYscFaO52OmxSDsNE2KZt9y+/F:TLC2KV5q/YLaO56s

MITRE ATT&CK Matrix

Tasks

OSZAR »