Hunt.io Details Cobalt Strike Infrastructure and Payloads Found in Exposed Directories

Summary
Hunt.io describes finding Cobalt Strike infrastructure and payloads in exposed directories, linking hosts through certificates, and analyzing PowerShell loaders, shellcode, and beacon behavior. It also shares indicators and defensive hunting recommendations.
Key points
- Hunt.io reports finding 404 Cobalt Strike-related configuration files and 1,224 associated malware instances in its data.
- A certificate search returned 3,355 IP-and-port combinations; 173 servers had exposed directories, according to the article.
- One exposed directory contained shortcut lures, a disguised installer, an encoded PowerShell payload, and a Cobalt Strike beacon.
- The analyzed loaders used hidden, encoded PowerShell, GZIP and XOR transformations, and in-memory code execution.
- The payloads used named pipes for local communication and connected to C2 infrastructure, including 141.98.197[.]31 on port 7785.
- Hunt.io recommends monitoring reused certificate fingerprints, exposed directories, encoded PowerShell, named pipes, memory injection, and suspicious network indicators.
Article Details
- Attack Vectors
- Malicious Windows shortcut files (Master.lnk and SetupOffice.lnk) were used to lure users into execution.
- A shortcut invoked PowerShell to download setup_office.exe from http://141.98.197[.]31:81/setup_office.exe and execute it.
- A second-stage PowerShell command used hidden, encoded execution; the script decoded, decompressed, and decrypted shellcode for in-memory execution.
- Cobalt Strike payloads communicated with C2 infrastructure, including 141.98.197[.]31 on port 7785.
- Defensive Notes
- Monitor for reuse of the identified Cobalt Strike certificate subjects and fingerprints across hosts.
- Disable public directory listing and restrict access to directories containing administrative or executable files.
- Enable detailed PowerShell logging and alert on combined -encodedcommand, -nop, and -w hidden flags.
- Log named-pipe creation and investigate unusual randomized pipe names.
- Monitor for VirtualAlloc and VirtualProtect activity initiated by PowerShell or unknown binaries, particularly alongside suspicious network connections.
- Review outbound HTTP traffic for the reported Internet Explorer-like User-Agent and uncommon ports, including 7785, 8080, and 14323.
- Correlate filenames, certificate fingerprints, and port data to identify related infrastructure.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 1[.]92[.]137[.]130 | Listed as confirmed active or historical Cobalt Strike infrastructure. |
| IPV4 | 103[.]149[.]93[.]146 | Listed as confirmed active or historical Cobalt Strike infrastructure. |
| IPV4 | 106[.]52[.]24[.]141 | Listed as confirmed active or historical Cobalt Strike infrastructure. |
| IPV4 | 107[.]148[.]35[.]2 | Listed as confirmed active or historical Cobalt Strike infrastructure. |
| IPV4 | 116[.]62[.]42[.]4 | Listed as confirmed active or historical Cobalt Strike infrastructure. |
| IPV4 | 118[.]25[.]10[.]65 | Listed as confirmed active or historical Cobalt Strike infrastructure. |
| IPV4 | 124[.]221[.]32[.]87 | Listed as confirmed active or historical Cobalt Strike infrastructure. |
| IPV4 | 141[.]98[.]197[.]31 | Cobalt Strike C2 server and host of an exposed directory containing malware components. |
| IPV4 | 150[.]158[.]21[.]250 | Listed as confirmed active or historical Cobalt Strike infrastructure. |
| IPV4 | 39[.]104[.]200[.]45 | Listed as confirmed active or historical Cobalt Strike infrastructure. |
| IPV4 | 43[.]199[.]214[.]90 | Listed as confirmed active or historical Cobalt Strike infrastructure. |
| IPV4 | 45[.]118[.]144[.]151 | Listed as confirmed active or historical Cobalt Strike infrastructure. |
| IPV4 | 47[.]101[.]187[.]187 | Listed as confirmed active or historical Cobalt Strike infrastructure. |
| IPV4 | 47[.]103[.]218[.]35 | Host flagged High Risk for confirmed Cobalt Strike activity, including C2 on port 8080. |
| IPV4 | 47[.]129[.]171[.]26 | Listed as confirmed active or historical Cobalt Strike infrastructure. |
| IPV4 | 58[.]87[.]103[.]59 | Listed as confirmed active or historical Cobalt Strike infrastructure. |
| IPV4 | 62[.]234[.]150[.]115 | Listed as confirmed active or historical Cobalt Strike infrastructure. |
| SHA256 | 56a06a233bd30f693de25ef12cc19e8b2c92d3eb97dd969a2578df084c376478 | Certificate fingerprint identified by the article as associated with Cobalt Strike deployments. |
| SHA256 | 87f2085c32b6a2cc709b365f55873e207a9caa10bffecf2fd16d3cf9d94d390c | Certificate fingerprint identified by the article as associated with Cobalt Strike deployments. |
| URL | hxxp[:]//141[.]98[.]197[.]31:81/setup_office[.]exe | Payload download URL used by the malicious shortcut to retrieve setup_office.exe. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationPayloads were concealed using Base64 encoding, GZIP compression, and XOR encryption.T1059.001 · PowerShellPowerShell was invoked with hidden and encoded-command options to run obfuscated payloads.T1071.001 · Web ProtocolsThe shellcode used web-related networking functions and a browser-like User-Agent for C2 communication.T1105 · Ingress Tool TransferPowerShell used Invoke-WebRequest to download setup_office.exe from the C2 host.T1140 · Deobfuscate/Decode Files or InformationThe PowerShell stages decoded, decompressed, and XOR-decrypted payload data before execution.T1204.002 · Malicious FileUsers were lured into executing malicious shortcut files such as Master.lnk and SetupOffice.lnk.T1571 · Non-Standard PortCobalt Strike beacons used uncommon ports, including 7785 and 14323.T1573 · Encrypted ChannelThe article reports SSL/TLS-protected C2 communications using certificates labeled Major Cobalt Strike.T1620 · Reflective Code LoadingThe loader allocated executable memory and ran decrypted code directly from memory.
Malware
Products
Microsoft Windowsincludes six malware components totaling 10 MB. The delivery files (Master.lnk and SetupOffice.lnk) are Windows shortcuts designed to trick users through social engineering, while 111.out is a Linux ELF executablePowerShellUsing AttackCaptureâ¢, we scanned exposed directories and pulled real files attackers left behind: PowerShell loaders, shortcut lures, and configuration scripts used in active campaigns. By connecting those files to