Skip to content

Commit

Permalink
Updated 2023-09-28-IOCs-for-IcedID-with-KeyholeVNC-and-Cobalt-Strike.txt
Browse files Browse the repository at this point in the history
  • Loading branch information
brad-duncan authored Jan 29, 2024
1 parent bcb66d4 commit c165065
Showing 1 changed file with 7 additions and 2 deletions.
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
2023-08-29 (TUESDAY): ICEDID (BOKBOT) INFECTION WITH KEYHOLE VNC AND COBALT STRIKE
2023-09-28 (TUESDAY): ICEDID (BOKBOT) INFECTION WITH KEYHOLE VNC AND COBALT STRIKE

REFERENCES:

- https://www.linkedin.com/posts/unit42_icedid-bokbot-backconnect-activity-7114605962115616768-ZK1o
- https://twitter.com/Unit42_Intel/status/1707898425973280907

INFECTION CHAIN:

Expand Down Expand Up @@ -91,4 +96,4 @@ BACKCONNECT AND KEYHOLE VNC TRAFFIC:

COBALT STRIKE TRAFFIC:

- 141.98.80[.]158 port 443 - umomrmwa[.]com - TLSv1.2 traffic using Let's Encrypt certificate
- 141.98.80[.]158 port 443 - umomrmwa[.]com - TLSv1.2 traffic using Let's Encrypt certificate

0 comments on commit c165065

Please sign in to comment.