Cobalt Strikes Again: An Analysis of Obfuscated Malware
ID: 46809460-5b45-5996-9b9d-795867f15691
STIX ID: report--46809460-5b45-5996-9b9d-795867f15691
Feed Name: Huntress Blog
This report walks through a multi-stage Cobalt Strike infection discovered via a RunOnce registry entry that loaded a Base64 PowerShell loader which reconstructed payload data from ~662 registry values. Analysts recovered and reverse-engineered five binaries (small .NET stager, larger .NET loader, Delphi binary, injected 32-bit DLLs and a reflective loader), confirmed Cobalt Strike via a parser, and extracted IOCs and TTPs including named-pipe defaults, HTTP(s) beaconing with an Avant Browser user-agent, and C2 IP details; numerous evasion techniques (heavy obfuscation, sleep-based anti-analysis, reflective loading, runtime API resolution, process injection) were observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
