Identifying Cobalt Strike team servers in the wild
ID: 85d0667b-85c4-56d4-b710-9409197b1c02
STIX ID: report--85d0667b-85c4-56d4-b710-9409197b1c02
Feed Name: Fox-IT blog
Threat Score
Fox-IT describes how an unintended extraneous whitespace in NanoHTTPD-based Cobalt Strike team server HTTP responses allowed reliable fingerprinting of public Cobalt Strike C2 servers; the post details historical scan results (7,718 hosts observed between 2015–2019), provides example IPs tied to known actors, and offers a Snort detection rule and investigative guidance to retroactively identify potential compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
