Cobalt Strike Beacon Detected - 101[.]43[.]1[.]44:8007 - RedPacket Security
Common Information
Type Value
UUID 48df958a-99d9-4a93-b399-64207e18c7dc
Fingerprint 414b5b625f84cecd
Analysis status DONE
Considered CTI value 0
Text language
Published Oct. 30, 2024, 12:03 a.m.
Added to db Oct. 30, 2024, 1:22 a.m.
Last updated Nov. 18, 2024, 4:26 p.m.
Headline Cobalt Strike Beacon Detected – 101[.]43[.]1[.]44:8007
Title Cobalt Strike Beacon Detected - 101[.]43[.]1[.]44:8007 - RedPacket Security
Detected Hints/Tags/Attributes 22/2/8
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 361 RedPacket Security https://www.redpacketsecurity.com/feed/ 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details Domain 2
gateway.gatshandong.xyz
Details Domain 2
tysfrz.isdapp.shandong.gov.cn
Details Domain 2
api-post.gatshandong.xyz
Details File 384
security.txt
Details File 343
process-inject.exe
Details IPv4 2
101.43.1.44
Details Url 2
https://tysfrz.isdapp.shandong.gov.cn
Details Url 2
https://tysfrz.isdapp.shandong.gov.cn/jis-web/login