TF-1932616
high
📛 Threat Title
Cobalt Strike: URL that is used for botnet Command&control (C&C) http://39.100.66.238:80/GrLX
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Cobalt Strike (aliases: Agentemis,BEACON,CobaltStrike,cobeacon). Confidence: 75. First seen: 2026-09-25 03:05:33 UTC. Reporter: abuse_ch. Tags: CobaltStrike.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
url
http://39.100.66.238:80/grlx
IOC database
- Type
- url
- Value
http://39.100.66.238:80/grlx- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- URL that is used for botnet Command&control (C&C) attributed to Cobalt Strike
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- External reference ThreatFox IOCs
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Cobalt Strike (aliases: Agentemis,BEACON,CobaltStrike,cobeacon). Confidence: 75. First seen: 2026-09-25 03:05:33 UTC. Reporter: abuse_ch. Tags: CobaltStrike.
Remediations (10)
-
web:8bitsecurity.com
At scale, hunting for Cobalt Strike beacons across large and heterogeneous environments presents a non-trivial challenge for threat hunting teams. But with that comes a great amount of creativity and opportunity. At its core, Cobalt Strikefunctions as the command-and-control (C2) platform orchestrating adversary operations.
-
web:github.com
Cobalt Strike is threat emulation software. Red teams and penetration testers use Cobalt Strike to demonstrate the risk of a breach and evaluate mature security programs. Cobalt Strike exploits network vulnerabilities, launches spear phishing campaigns, hosts web drive-by attacks, and generates malware infected files from a powerful graphical user interface that encourages collaboration and ...
-
web:thedfirreport.com
Cobalt Strike is dependent on Java to run both the client graphical user interface (GUI) and the team server. When we scan a Cobalt Strike server using JARM, the results we get back are dependent on the Java version that is used .
-
web:www.cobaltstrike.com
Cobalt Strike was one of the first public red team command and control frameworks. In 2020, Fortra (the new face of HelpSystems) acquired Cobalt Strike to add to its Core Security portfolio and pair with Core Impact. Today, Cobalt Strike is the go-to red team tool for many U.S. government, large business, and consulting organizations.
-
web:www.elastic.co
Cobalt Strike is a threat emulation platform commonly modified and used by adversaries to conduct network attack and exploitation campaigns. This rule detects a network activity algorithm leveraged by Cobalt Strike implant beacons for command and control.
-
web:www.elastic.co
Cobalt Strike is a threat emulation platform commonly modified and used by adversaries to conduct network attack and exploitation campaigns. This rule detects a network activity algorithm leveraged by Cobalt Strike implant beacons for command and control.
-
web:www.extrahop.com
Cobalt Strike C&C HTTP Connection Cobalt Strike is associated with pen testing, security assessments, and sometimes persistent, planned attacks. Malleable C&C profiles for configuring C&C traffic are publicly available and well known. Through a persistent C&C channel, an attacker can remotely control a device and gain an entry point for further attacks on the network.
-
web:www.quorumcyber.com
The primary malicious operations associated with Cobalt Strike occur via its ability to establish command and control (C2) communications with target networks, thus creating a persistent access channel between the target and the threat actor.
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
-
web:www.spamhaus.org
Botnet Threat Update January to June 2026 Between Jan-Jun 2026 botnet C&C servers observed decreased -30% to 14,952. Sliver overtook Cobalt Strike for the #1 spot (+58%). Meanwhile .cn botnet C&C domains surged +771% and India's PDR registrar saw a +901% spike in abused registrations - though REGRU bucked the trend with a -90% reduction. Read the latest report to learn more.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.