PULSE NAME
Hiding a beacon in a jquery
WHITE AlienVault 2018-11-26 Modified: 2018-11-26
5
IOCs
LOW VOLUME
It’s easy to find yourself as a malware researcher looking at some unimaginative samples, which can be good for learning but sometimes you find one that someone actually invested some time into. While ripping this apart I noticed that most of the setup was mimicking a CobaltStrike setup from a redteam blog.
Indicators of Compromise (1 / 5 total)
All YARA FileHash-SHA256 hostname
TYPEINDICATORDESCRIPTIONCREATED
hostname jquery.amazoncdn.org 2018-11-26