TF-1932617
high
📛 Threat Title
Cobalt Strike: URL that is used for botnet Command&control (C&C) http://39.100.66.238:80/ptj
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Cobalt Strike (aliases: Agentemis,BEACON,CobaltStrike,cobeacon). Confidence: 75. First seen: 2026-09-25 03:05:34 UTC. Reporter: abuse_ch. Tags: CobaltStrike.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
url
http://39.100.66.238:80/ptj
IOC database
- Type
- url
- Value
http://39.100.66.238:80/ptj- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- URL that is used for botnet Command&control (C&C) attributed to Cobalt Strike
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- External reference ThreatFox IOCs
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Cobalt Strike (aliases: Agentemis,BEACON,CobaltStrike,cobeacon). Confidence: 75. First seen: 2026-09-25 03:05:34 UTC. Reporter: abuse_ch. Tags: CobaltStrike.
Remediations (10)
-
web:8bitsecurity.com
At scale, hunting for Cobalt Strike beacons across large and heterogeneous environments presents a non-trivial challenge for threat hunting teams. But with that comes a great amount of creativity and opportunity. At its core, Cobalt Strikefunctions as the command-and-control (C2) platform orchestrating adversary operations.
-
web:arxiv.org
This paper presents a machine learning-based method to detect Cobalt Strike Command and Control activity based only on widely used network traffic metadata. The proposed method is , to the best of our knowledge, the first of its kind that is able to adapt the model it uses to the observed traffic to optimize its performance.
-
web:securereading.com
Malicious Command Server Identified Threat intelligence monitoring has detected a new command-and-control (C2) infrastructure associated with Cobalt Strike , a powerful adversary simulation tool frequently weaponized by threat actors. Security analysts flagged the following indicator as malicious: IOC: 43.249.175.87:39816 Threat Type: Botnet Command-and-Control Confidence Level: High (100%) ASN ...
-
web:threatfox.abuse.ch
You are viewing the ThreatFox database entry for ip:port 39.100.66.238:443.
-
web:threatfox.abuse.ch
ThreatFox IOC Database You are viewing the ThreatFox database entry for ip:port 39.100.66.238:80. Database Entry
-
web:undercodetesting.com
Introduction: Command and Control (C2) frameworks are the linchpin of modern cyberattacks, enabling threat actors to maintain persistence and execute objectives on compromised networks.
-
web:www.elastic.co
Cobalt Strike is a penetration testing tool often repurposed by attackers for malicious activities, particularly for establishing command and control (C2) channels. Adversaries exploit its beaconing feature to communicate with compromised systems using common protocols like HTTP or TLS. The detection rule identifies suspicious network patterns, such as specific domain naming conventions ...
-
web:www.quorumcyber.com
The primary malicious operations associated with Cobalt Strike occur via its ability to establish command and control (C2) communications with target networks, thus creating a persistent access channel between the target and the threat actor.
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
-
web:www.spamhaus.org
Botnet Threat Update January to June 2026 Between Jan-Jun 2026 botnet C&C servers observed decreased -30% to 14,952. Sliver overtook Cobalt Strike for the #1 spot (+58%). Meanwhile .cn botnet C&C domains surged +771% and India's PDR registrar saw a +901% spike in abused registrations - though REGRU bucked the trend with a -90% reduction. Read the latest report to learn more.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.