PULSE NAME
Oz Batch: 50 IOCs (avg BDE: 85)
WHITE Cobalt pduggusa 2026-01-13 Modified: 2026-02-12
26
IOCs
MEDIUM VOLUME
**Pulse Description:** This OTX pulse identifies a collection of 50 indicators linked to Cobalt infrastructure, with a notable average BDE (Big Data analytics Energy) Score of 85. The indicators include various types such as IPs, domains, URLs, and hashes associated with Cobalt Strike, AsyncRAT, and other malware frameworks prevalent in recent campaigns. The presence of these indicators suggests ongoing malicious activity, warranting immediate analysis and monitoring using the relevant MITRE ATT&CK techniques. BDE Score: 85, Detection Timestamp: [Insert Timestamp Here]
Indicators of Compromise (26)
All hostname domain FileHash-SHA256 FileHash-MD5
TYPEINDICATORDESCRIPTIONCREATED
hostname readconfig.x1s.icu BDE: 85 2026-01-13
hostname bacan4d.jp.net BDE: 85 2026-01-13
hostname crwqin.ru.com BDE: 85 2026-01-13
hostname mdf.uk.com BDE: 85 2026-01-13
hostname xar.uk.com BDE: 85 2026-01-13
hostname ubdofr.sa.com BDE: 85 2026-01-13
domain 789bet-trangchu.vip BDE: 85 2026-01-13
domain alloparentsbebe.org BDE: 85 2026-01-13
domain okvip168th.net BDE: 85 2026-01-13
domain open88top1.com BDE: 85 2026-01-13
hostname xacmgm.za.com BDE: 85 2026-01-13
hostname ns1.mhtmzl.top BDE: 85 2026-01-13
hostname ns2.mhtmzl.top BDE: 85 2026-01-13
domain hostikslu.is BDE: 85 2026-01-13
domain eqp.lol BDE: 85 2026-01-13
domain securityfenceandwelding.com BDE: 85 2026-01-13
domain gonebornes.com BDE: 85 2026-01-13
domain fbnmoon.coupons BDE: 85 2026-01-13
domain fbnmoon.xyz BDE: 85 2026-01-13
domain fbnmoon.world BDE: 85 2026-01-13
domain fbnmoon.top BDE: 85 2026-01-13
domain fbnmoon.space BDE: 85 2026-01-13
domain fbnmoon.fun BDE: 85 2026-01-13
hostname backend-knwv.onrender.com BDE: 85 2026-01-13
FileHash-SHA256 8fa4c7d17970cf92b74ee61b5e80b60e887b4b2648b485cbe1100ea1b5556357 BDE: 85 2026-01-13
FileHash-MD5 0042c8c9f8a16f0b02a917fecdf145bc BDE: 85 2026-01-13