PULSE NAME
Oz Batch: 50 IOCs (avg BDE: 85)
WHITE Cobalt pduggusa 2026-02-05 Modified: 2026-03-07
24
IOCs
MEDIUM VOLUME
**Pulse Description: Cobalt Strike Infrastructure Detection** This pulse identifies 50 indicators associated with Cobalt Strike infrastructure, including IPs and domains utilized for command and control operations. The detected C2 frameworks include notable threats such as Sliver, Bashlite, DCRat, and NjRAT, indicating a sophisticated adversary profile. The average BDE (Big Data analytics Energy) score for these indicators is 85, highlighting their potential impact. This infrastructure suggests active campaigns likely aligned with MITRE ATT&CK techniques related to remote access and execution. Detection Timestamp: [Insert timestamp here] BDE Score: 85
Indicators of Compromise (24)
All hostname domain
TYPEINDICATORDESCRIPTIONCREATED
hostname api.cloudtrafficservice.com BDE: 85 2026-02-05
hostname www.zyhservers.top BDE: 85 2026-02-05
hostname nssmsndnebev.duckdns.org BDE: 85 2026-02-05
hostname fgaehr4awhuw5he.duckdns.org BDE: 85 2026-02-05
hostname fgeaghrwhgrw.duckdns.org BDE: 85 2026-02-05
domain tt-ynl.top BDE: 85 2026-02-05
domain quotesdcm.top BDE: 85 2026-02-05
domain t0up.top BDE: 85 2026-02-05
hostname relay.t0up.top BDE: 85 2026-02-05
domain access-hub.lol BDE: 85 2026-02-05
hostname als.skjeelancipla.com.lk BDE: 85 2026-02-05
hostname log.skjeelancipla.com.lk BDE: 85 2026-02-05
hostname reg.skjeelancipla.com.lk BDE: 85 2026-02-05
hostname tog.skjeelancipla.com.lk BDE: 85 2026-02-05
domain inconsk.cyou BDE: 85 2026-02-05
domain cheship.cyou BDE: 85 2026-02-05
domain molewyn.cyou BDE: 85 2026-02-05
domain tasselg.cyou BDE: 85 2026-02-05
domain troyouc.cyou BDE: 85 2026-02-05
domain dreamlm.cyou BDE: 85 2026-02-05
domain swedisc.cyou BDE: 85 2026-02-05
domain thoughg.cyou BDE: 85 2026-02-05
domain trainen.cyou BDE: 85 2026-02-05
hostname utils.myvnc.com BDE: 85 2026-02-05