Hunt.io Details Cobalt Strike Infrastructure and Payloads Found in Exposed Directories

· Original article ↗

Summary

Hunt.io describes finding Cobalt Strike infrastructure and payloads in exposed directories, linking hosts through certificates, and analyzing PowerShell loaders, shellcode, and beacon behavior. It also shares indicators and defensive hunting recommendations.

Key points

  • Hunt.io reports finding 404 Cobalt Strike-related configuration files and 1,224 associated malware instances in its data.
  • A certificate search returned 3,355 IP-and-port combinations; 173 servers had exposed directories, according to the article.
  • One exposed directory contained shortcut lures, a disguised installer, an encoded PowerShell payload, and a Cobalt Strike beacon.
  • The analyzed loaders used hidden, encoded PowerShell, GZIP and XOR transformations, and in-memory code execution.
  • The payloads used named pipes for local communication and connected to C2 infrastructure, including 141.98.197[.]31 on port 7785.
  • Hunt.io recommends monitoring reused certificate fingerprints, exposed directories, encoded PowerShell, named pipes, memory injection, and suspicious network indicators.

Article Details

Attack Vectors
  • Malicious Windows shortcut files (Master.lnk and SetupOffice.lnk) were used to lure users into execution.
  • A shortcut invoked PowerShell to download setup_office.exe from http://141.98.197[.]31:81/setup_office.exe and execute it.
  • A second-stage PowerShell command used hidden, encoded execution; the script decoded, decompressed, and decrypted shellcode for in-memory execution.
  • Cobalt Strike payloads communicated with C2 infrastructure, including 141.98.197[.]31 on port 7785.
Defensive Notes
  • Monitor for reuse of the identified Cobalt Strike certificate subjects and fingerprints across hosts.
  • Disable public directory listing and restrict access to directories containing administrative or executable files.
  • Enable detailed PowerShell logging and alert on combined -encodedcommand, -nop, and -w hidden flags.
  • Log named-pipe creation and investigate unusual randomized pipe names.
  • Monitor for VirtualAlloc and VirtualProtect activity initiated by PowerShell or unknown binaries, particularly alongside suspicious network connections.
  • Review outbound HTTP traffic for the reported Internet Explorer-like User-Agent and uncommon ports, including 7785, 8080, and 14323.
  • Correlate filenames, certificate fingerprints, and port data to identify related infrastructure.

Indicators of compromise

TypeIndicatorContext
IPV41[.]92[.]137[.]130Listed as confirmed active or historical Cobalt Strike infrastructure.
IPV4103[.]149[.]93[.]146Listed as confirmed active or historical Cobalt Strike infrastructure.
IPV4106[.]52[.]24[.]141Listed as confirmed active or historical Cobalt Strike infrastructure.
IPV4107[.]148[.]35[.]2Listed as confirmed active or historical Cobalt Strike infrastructure.
IPV4116[.]62[.]42[.]4Listed as confirmed active or historical Cobalt Strike infrastructure.
IPV4118[.]25[.]10[.]65Listed as confirmed active or historical Cobalt Strike infrastructure.
IPV4124[.]221[.]32[.]87Listed as confirmed active or historical Cobalt Strike infrastructure.
IPV4141[.]98[.]197[.]31Cobalt Strike C2 server and host of an exposed directory containing malware components.
IPV4150[.]158[.]21[.]250Listed as confirmed active or historical Cobalt Strike infrastructure.
IPV439[.]104[.]200[.]45Listed as confirmed active or historical Cobalt Strike infrastructure.
IPV443[.]199[.]214[.]90Listed as confirmed active or historical Cobalt Strike infrastructure.
IPV445[.]118[.]144[.]151Listed as confirmed active or historical Cobalt Strike infrastructure.
IPV447[.]101[.]187[.]187Listed as confirmed active or historical Cobalt Strike infrastructure.
IPV447[.]103[.]218[.]35Host flagged High Risk for confirmed Cobalt Strike activity, including C2 on port 8080.
IPV447[.]129[.]171[.]26Listed as confirmed active or historical Cobalt Strike infrastructure.
IPV458[.]87[.]103[.]59Listed as confirmed active or historical Cobalt Strike infrastructure.
IPV462[.]234[.]150[.]115Listed as confirmed active or historical Cobalt Strike infrastructure.
SHA25656a06a233bd30f693de25ef12cc19e8b2c92d3eb97dd969a2578df084c376478Certificate fingerprint identified by the article as associated with Cobalt Strike deployments.
SHA25687f2085c32b6a2cc709b365f55873e207a9caa10bffecf2fd16d3cf9d94d390cCertificate fingerprint identified by the article as associated with Cobalt Strike deployments.
URLhxxp[:]//141[.]98[.]197[.]31:81/setup_office[.]exePayload download URL used by the malicious shortcut to retrieve setup_office.exe.

MITRE ATT&CK

Malware

Products

Tools

Related Articles