PULSE NAME
Cobalt Strike C2 | 03/27/2023
WHITE IronNetTR 2023-04-03 Modified: 2023-05-03
0
IOCs
LOW VOLUME
IronNet Threat Analysts scan the web searching for hosts that are serving Cobalt Strike beacons. We then pull them down and extract the beacon config for analysis. The IPs and domains in this pulse are the C2 hosts extracted from those configs. These servers were scanned the week of 03/27/2023.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Cobalt Strike - S0154
Indicators of Compromise (0)
All
No indicators.