TF-1932797
high
📛 Threat Title
Cobalt Strike: Domain that is used for botnet Command&control (C&C) a.bc.6a73dbe.www.aioperao.com
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Cobalt Strike (aliases: Agentemis,BEACON,CobaltStrike,cobeacon). Confidence: 100. First seen: 2026-09-25 11:47:16 UTC. Reporter: anonymous.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
a.bc.6a73dbe.www.aioperao.com
IOC database
- Type
- domain
- Value
a.bc.6a73dbe.www.aioperao.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain that is used for botnet Command&control (C&C) attributed to Cobalt Strike
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Cobalt Strike (aliases: Agentemis,BEACON,CobaltStrike,cobeacon). Confidence: 100. First seen: 2026-09-25 11:47:16 UTC. Reporter: anonymous.
Remediations (10)
-
web:8bitsecurity.com
At scale, hunting for Cobalt Strike beacons across large and heterogeneous environments presents a non-trivial challenge for threat hunting teams. But with that comes a great amount of creativity and opportunity. At its core, Cobalt Strikefunctions as the command-and-control (C2) platform orchestrating adversary operations.
-
web:feed.craftedsignal.io
This brief documents the detection of Cobalt Strike command and control activity through identifying specific domain naming conventions used by its implant beacons, indicative of network attack and exploitation campaigns.
-
web:feed.craftedsignal.io
Adversaries, notably FIN7, deploy Cobalt Strike beacons on compromised systems to establish command and control (C2) channels, utilizing specific network activity algorithms and domain naming conventions for communication over protocols like HTTP or TLS, posing a critical risk of further compromise and data exfiltration.
-
web:github.com
Shellcode loaders to add in Cobalt Strike before generating your shellcode which are used to reflectively generate shellcode for added obfuscation, encryption, and ultimately better evasion.
-
web:morimori-dev.github.io
Cobalt Strike is a commercial adversary simulation framework widely used in authorized red team engagements. Understanding its architecture, Beacon payloads, and post-exploitation capabilities is essential for both red teamers and defenders (blue team).
-
web:securereading.com
Cobalt Strike C2 server detected Security monitoring identifies a new command-and-control endpoint linked to one of the most widely abused post-exploitation frameworks.
-
web:undercodetesting.com
Develop practical skills for hunting and eradicating common Cobalt Strike persistence mechanisms. You Should Know: Identifying Cobalt Strike Team Servers with JA3/S Hashes Cobalt Strike beacons often use a unique JA3/S fingerprint, a method of identifying SSL/TLS client/server interactions.
-
web:www.elastic.co
Cobalt Strike is a penetration testing tool often repurposed by attackers for malicious activities, particularly for establishing command and control (C2) channels. Adversaries exploit its beaconing feature to communicate with compromised systems using common protocols like HTTP or TLS. The detection rule identifies suspicious network patterns, such as specific domain naming conventions ...
-
web:www.quorumcyber.com
The primary malicious operations associated with Cobalt Strike occur via its ability to establish command and control (C2) communications with target networks, thus creating a persistent access channel between the target and the threat actor.
-
web:www.spamhaus.org
Botnet Threat Update January to June 2026 Between Jan-Jun 2026 botnet C&C servers observed decreased -30% to 14,952. Sliver overtook Cobalt Strike for the #1 spot (+58%). Meanwhile .cn botnet C&C domains surged +771% and India's PDR registrar saw a +901% spike in abused registrations - though REGRU bucked the trend with a -90% reduction. Read the latest report to learn more.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.