Tracking a Cobalt Strike Beacon via Shodan
Intro
Host: 107.149.192.54
Hostname: img.bc8.in
Ports: 443, 80, 888, 3306 (mysql), 7443 (cobaltstrike)
Watermark: 391144938
Enumeration
https://www.shodan.io/host/107.149.192.54
This Cobalt Strike beacon is using WerFault.exe and gpupdate.exe to spaw...
xoravery.hashnode.dev1 min read