TF-1932657
high
📛 Threat Title
Cobalt Strike: Domain that is used for botnet Command&control (C&C) i.gckni.com
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Cobalt Strike (aliases: Agentemis,BEACON,CobaltStrike,cobeacon). Confidence: 75. First seen: 2026-09-25 03:46:53 UTC. Last seen: 2026-09-25 11:47:33 UTC. Reporter: abuse_ch. Tags: CobaltStrike, drb-ra.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
i.gckni.com
IOC database
- Type
- domain
- Value
i.gckni.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain that is used for botnet Command&control (C&C) attributed to Cobalt Strike
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Cobalt Strike (aliases: Agentemis,BEACON,CobaltStrike,cobeacon). Confidence: 75. First seen: 2026-09-25 03:46:53 UTC. Last seen: 2026-09-25 06:47:38 UTC. Reporter: abuse_ch. Tags: CobaltStrike, drb-ra.
Remediations (10)
-
web:detection.fyi
Cobalt Strike is a threat emulation platform commonly modified and used by adversaries to conduct network attack and exploitation campaigns. This rule detects a network activity algorithm leveraged by Cobalt Strike implant beacons for command and control.
-
web:feed.craftedsignal.io
This brief documents the detection of Cobalt Strike command and control activity through identifying specific domain naming conventions used by its implant beacons, indicative of network attack and exploitation campaigns.
-
web:morimori-dev.github.io
Cobalt Strike is a commercial adversary simulation framework widely used in authorized red team engagements. Understanding its architecture, Beacon payloads, and post-exploitation capabilities is essential for both red teamers and defenders (blue team).
-
web:unit42.paloaltonetworks.com
Cobalt Strike is a commercial software framework that enables security professionals like red team members to simulate attackers embedding themselves in a network environment. However, threat actors continue to use cracked versions of Cobalt Strike in real-world attacks.
-
web:www.elastic.co
Cobalt Strike is a penetration testing tool often repurposed by attackers for malicious activities, particularly for establishing command and control (C2) channels. Adversaries exploit its beaconing feature to communicate with compromised systems using common protocols like HTTP or TLS. The detection rule identifies suspicious network patterns, such as specific domain naming conventions ...
-
web:www.elastic.co
Cobalt Strike is a threat emulation platform commonly modified and used by adversaries to conduct network attack and exploitation campaigns. This rule detects a network activity algorithm leveraged by Cobalt Strike implant beacons for command and control.
-
web:www.manageengine.com
The Cobalt Strike beacon is a small implant that establishes a command-and-control channel back to a team server operated by the attacker. It supports a wide range of post-exploitation capabilities: process injection, credential dumping, lateral movement, privilege escalation, and file transfer.
-
web:www.securityscientist.net
How to Detect and Remove Cobalt Strike from Your Environment A practical guide to defending against Cobalt Strike . Covers attack patterns, detection strategies, and prioritised mitigations .
-
web:www.spamhaus.org
Botnet Threat Update January to June 2026 Between Jan-Jun 2026 botnet C&C servers observed decreased -30% to 14,952. Sliver overtook Cobalt Strike for the #1 spot (+58%). Meanwhile .cn botnet C&C domains surged +771% and India's PDR registrar saw a +901% spike in abused registrations - though REGRU bucked the trend with a -90% reduction. Read the latest report to learn more.
-
web:www.vectra.ai
Cobalt Strike is a commercial product, and legitimate use is typically licensed through the vendor. Organizations evaluating cost should plan for licensing plus the operational overhead of responsible use (scope control, logging, and detection validation during exercises).
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.