00000019.00000003.506676110.000000000626D000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x2d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499865318.0000000006E54000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xf0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.498703501.000000000583F000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x90e:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500021102.0000000006E34000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x2b78:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500164196.0000000006E17000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x2800:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.509313999.0000000005BBF000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x500:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499436698.0000000006E9B000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x13b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x4878:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7d50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xb238:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xe720:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x11c08:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15100:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500090549.0000000006E2A000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x2f70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500504965.0000000006DD2000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xb40:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499684731.0000000006E71000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x7b8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.509423270.0000000005BBF000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x500:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500246766.0000000006E08000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1578:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000002.568757163.0000000006E43000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xbf8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.505927561.000000000636D000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xe88:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x33f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5958:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7ec0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xa428:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xc990:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xef08:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x11480:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x139f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15f70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x184f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1aa80:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1d008:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1f590:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x21b28:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x240c0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500477251.0000000006DD8000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x11a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.508961693.0000000005CB9000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xb70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500075794.0000000006E2E000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x2368:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499611659.0000000006E81000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xe20:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500491953.0000000006DD5000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xe68:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499493418.0000000006E94000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1a20:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.508307572.0000000005E40000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x168:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500524387.0000000006DCF000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x818:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500409413.0000000006DE2000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xb78:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000009.00000002.556693839.0000000000F50000.00000004.00000020.00020000.00000000.sdmp | SUSP_PS1_Msdt_Execution_May22 | Detects suspicious calls of msdt.exe as seen in CVE-2022-30190 / Follina exploitation | Nasreddine Bencherchali, Christian Burkard | - 0x1cec:$a: PCWDiagnostic
- 0x3823:$a: PCWDiagnostic
- 0x553e:$a: PCWDiagnostic
- 0x1c84:$sa1: msdt.exe
- 0x1cc0:$sa1: msdt.exe
- 0x20da:$sa1: msdt.exe
- 0x380d:$sa1: msdt.exe
- 0x1d92:$sb3: IT_BrowseForFile=
- 0x3876:$sb3: IT_BrowseForFile=
|
00000009.00000002.556693839.0000000000F50000.00000004.00000020.00020000.00000000.sdmp | JoeSecurity_Follina | Yara detected Microsoft Office Exploit Follina / CVE-2022-30190 | Joe Security | |
00000019.00000003.503297847.00000000066F5000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x8e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3320:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5d68:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x87b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xb1f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xdc40:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x10688:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x130e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15b38:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18590:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1afe8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1da50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x204b8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x22f20:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x25988:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x283f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2ae68:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2d8e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x30358:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x32dd0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x35858:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500310887.0000000006DF5000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1008:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.505719347.0000000006392000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1658:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3bf0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6188:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8720:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xacc8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xd270:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xf818:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x11dc0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x14378:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x16930:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18ee8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b4a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1da58:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x20020:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x225e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x24bb0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x27178:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x29740:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2bd18:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2e2f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x308c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500548113.0000000006DC9000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000009.00000002.585006641.0000000003700000.00000004.00000020.00020000.00000000.sdmp | SUSP_PS1_Msdt_Execution_May22 | Detects suspicious calls of msdt.exe as seen in CVE-2022-30190 / Follina exploitation | Nasreddine Bencherchali, Christian Burkard | - 0x28b2:$a: PCWDiagnostic
- 0x2888:$sa1: msdt.exe
- 0x2956:$sb3: IT_BrowseForFile=
|
00000009.00000002.585006641.0000000003700000.00000004.00000020.00020000.00000000.sdmp | JoeSecurity_Follina | Yara detected Microsoft Office Exploit Follina / CVE-2022-30190 | Joe Security | |
00000019.00000003.500261822.0000000006E04000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x21e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500418706.0000000006DDF000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x830:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000002.568673308.0000000006E23000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x398:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.507852725.0000000005EC1000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x17e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3700:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5618:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7530:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9448:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xb360:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xd288:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xf1b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x110d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x13000:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x14f28:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x16e50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18d88:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1acc0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1cbf8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1eb30:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x20a68:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x229a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x248e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x26830:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x28778:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000002.568682358.0000000006E26000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x780:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.508838061.0000000005C41000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x8f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2408:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3f20:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5a38:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7550:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9078:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xaba0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xc6c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xe1f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xfd18:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x11840:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x13378:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x14eb0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x169e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18520:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1a058:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1bb90:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1d6d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1f220:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x20d68:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x228b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499473983.0000000006E97000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1ee8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
0000001E.00000002.556428060.0000000002CE0000.00000040.00000400.00020000.00000000.sdmp | Cobaltbaltstrike_RAW_Payload_https_stager_x86 | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x0:$h01: FC E8 89 00 00 00 60 89 E5 31 D2 64 8B 52 30 8B 52 0C 8B 52 14 8B 72 28
|
0000001E.00000002.556428060.0000000002CE0000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
00000019.00000003.500155514.0000000006E1B000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1bd8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499623622.0000000006E7E000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x998:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.508459967.0000000005DBA000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1500:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3288:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000002.568748602.0000000006E40000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x7d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000002.568710134.0000000006E30000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x368:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.507100056.00000000060F1000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1210:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3428:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5640:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499889442.0000000006E4D000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x880:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3cb8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.506175810.00000000062EE000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xb20:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2fc8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5470:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7928:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9de0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xc298:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xe750:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x10c08:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x130c0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15588:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x17a50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x19f18:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1c3e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1e8b8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x20d90:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x23268:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x25740:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x27c28:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2a110:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2c5f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2eae0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.508628056.0000000005D0F000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xee8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2b60:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x47d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6450:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x80c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9d40:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xb9b8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xd630:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xf2b8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x10f40:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12bc8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x14850:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x164d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18170:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x19e08:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1baa0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1d738:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1f3d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x21078:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x22d20:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x249c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499641627.0000000006E7A000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1520:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499824941.0000000006E5D000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xdc8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.506705393.000000000618E000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1458:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3740:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5a28:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7d10:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9ff8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xc2f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xe5e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x108e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12bd8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x14ee0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x171e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x194f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b7f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1db10:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1fe28:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x22140:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x24458:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x26770:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x28a98:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2adc0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2d0e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.501596100.0000000006A80000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x11c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3fd0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6dd8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9be0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xc9f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xf810:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12628:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15440:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18258:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b080:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1dea8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x20cd0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x23af8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x26920:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x29748:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2c580:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2f3b8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x321f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x35028:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x37e60:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3ac98:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.501243619.0000000006B54000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1000:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3ed8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6db0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9c98:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xcb80:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xfa68:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12950:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15838:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18720:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b618:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1e510:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x21408:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x24300:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x271f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2a100:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500112961.0000000006E27000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x2b78:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499962160.0000000006E3E000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x27d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500328316.0000000006DF2000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xc90:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000002.568738886.0000000006E3C000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x13a8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.509561363.0000000005B0A000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x26ec8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x28800:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2a138:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2ba70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2d3a8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2ecf0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x30638:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x31f80:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.507377946.0000000006041000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x8f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2a28:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x4b60:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6c98:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8dd0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xaf08:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xd040:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xf178:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x112c0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x13408:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15550:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x17698:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x197e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b928:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1da80:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1fbd8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x21d30:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x23e88:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x25fe0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x28148:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000002.568792297.0000000006E50000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xcb8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000009.00000002.582026384.0000000001080000.00000004.00000020.00020000.00000000.sdmp | SUSP_PS1_Msdt_Execution_May22 | Detects suspicious calls of msdt.exe as seen in CVE-2022-30190 / Follina exploitation | Nasreddine Bencherchali, Christian Burkard | - 0x2338:$a: PCWDiagnostic
- 0x22d0:$sa1: msdt.exe
- 0x230c:$sa1: msdt.exe
- 0x2726:$sa1: msdt.exe
- 0x23de:$sb3: IT_BrowseForFile=
|
00000009.00000002.582026384.0000000001080000.00000004.00000020.00020000.00000000.sdmp | JoeSecurity_Follina | Yara detected Microsoft Office Exploit Follina / CVE-2022-30190 | Joe Security | |
00000019.00000003.499598965.0000000006E84000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x12b8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.504952600.000000000646C000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xb50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3228:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5900:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7fe8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xa6d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xcdb8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xf4a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x11b98:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x14290:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x16988:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x19080:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b778:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1de80:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x20588:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x22c90:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x25398:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x27aa0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2a1b8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2c8d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2efe8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x31700:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500604850.0000000006CB9000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x9f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3ac8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499944069.0000000006E41000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x2bf8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.504750760.00000000064EB000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x11e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3978:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6110:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x88a8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xb040:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xd7e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xff90:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12738:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x14ee0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x17698:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x19e50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1c608:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1edc0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x21588:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x23d50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x26518:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x28ce0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2b4a8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2dc80:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x30458:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x32c30:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.502123395.00000000068FF000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1058:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499912534.0000000006E47000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x20:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500175997.0000000006E14000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x2438:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.506567409.0000000006230000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x950:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2d18:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x50e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x74a8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9870:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xbc48:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xe020:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x103f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x127d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x14ba8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x16f80:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x19358:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b740:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1db28:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1ff10:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x222f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x246e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x26ad8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x28ed0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2b2c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2d6c0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499654163.0000000006E77000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x10a8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500392333.0000000006DE5000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xed0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500656702.0000000006C3A000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x9d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x39c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x69c0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x99c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xc9d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xf9d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x129f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15a08:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18a20:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1ba38:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1ea60:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x21a88:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x24ab0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x27ad8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2ab00:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2db38:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x30b70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x33ba8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x36bf0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x39c38:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3cc90:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500133947.0000000006E21000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x2398:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.507760692.0000000005EF2000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1410:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3368:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x52d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7238:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x91a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xb108:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xd070:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xefe8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x10f60:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12ed8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x14e50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x16dc8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18d40:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1acb8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1cc40:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1ebc8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x20b50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x22ad8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x24a60:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x269f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x28990:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499706418.0000000006E6E000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x350:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.504345055.000000000656C000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1670:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3eb8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6700:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8f48:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xb7a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xdff8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x10850:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x130a8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15910:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18178:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1a9e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1d248:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1fac0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x22338:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x24bb0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x27428:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x29cb0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2c538:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2edc0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x31648:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x33ed0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499750187.0000000006E67000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xaa0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499521324.0000000006E8E000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x10a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.508543817.0000000005DB8000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x770:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.501697332.0000000006A21000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1890:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x4648:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7400:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xa1b8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xcf70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xfd28:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12ae0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15898:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18660:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b428:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1e1f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x20fb8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x23d80:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x26b58:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x29930:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2c708:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2f4e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x322b8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x35090:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x37e78:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3ac60:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.501200856.0000000006C04000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xf10:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3e88:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6e10:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9da8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xcd40:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xfcd8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12c80:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15c28:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18bd0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1bb88:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1eb50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x21b18:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x24ae0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x27aa8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2aa70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2da38:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x30a10:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x339e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.509127714.0000000005BC0000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xf38:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2970:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x43a8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5de0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7828:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9270:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xacb8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xc700:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xe148:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xfb90:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x115d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x13030:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x14a88:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x164e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x17f38:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x199a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b408:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1ce70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1e8d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x20340:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x21db8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500032754.0000000006E31000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x2770:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000002.567918240.0000000006071000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x6e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.502899282.0000000006741000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1780:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x4228:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6cd0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9778:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xc220:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xecd8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x11790:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x14248:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x16d00:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x197c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1c290:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1ed58:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x21820:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x242f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x26dd0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x298a8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2c380:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2ee58:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x31930:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x34418:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x36f00:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.503663386.0000000006640000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1418:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3d80:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x66e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9050:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xb9b8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xe320:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x10c88:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x13600:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15f78:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x188f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b268:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1dbe0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x20568:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x22ef0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x25878:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x28200:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2ab88:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2d520:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2feb8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x32850:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x351e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500236769.0000000006E0B000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1920:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.507414149.0000000006071000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x6e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.509264079.0000000005B78000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x8e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2298:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3c50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5618:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6fe0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x89a8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xa370:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xbd38:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xd700:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xf0d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x10ab0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12488:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x13e60:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15838:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x17210:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18bf8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1a5e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1bfc8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1d9b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1f398:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x20d80:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.507996577.0000000005E41000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xfc0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2e18:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x4c70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6ac8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8920:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xa788:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xc5f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xe458:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x102c0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12128:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x13f90:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15df8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x17c70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x19ae8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b960:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1d7d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1f650:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x214d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x23360:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x251e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x27070:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499506056.0000000006E91000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1558:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.508112663.0000000005E1F000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xfc0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2de8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x4c10:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6a38:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8860:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xa688:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xc4b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xe2e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x10120:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x11f58:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x13d90:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15bc8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x17a00:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x19848:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b690:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1d4d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1f320:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x21168:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499764114.0000000006E64000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x658:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500280490.0000000006DFE000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1ab0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.507642082.0000000005F41000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x13d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x33a8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5380:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7358:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9330:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xb318:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xd300:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xf2e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x112d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x132b8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x152a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x17298:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x19290:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b288:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1d280:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1f278:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x21270:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x23278:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x25280:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000002.567865973.0000000005CB9000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xb70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500590066.0000000006DBF000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x8b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3bb8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.503439579.00000000066C0000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xe80:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3890:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6298:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8ca0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xb6a8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xe0b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x10ac8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x134e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15ef8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18910:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b328:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1dd40:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x20768:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x23190:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x25bb8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x285e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2b008:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2da40:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x30478:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x32eb0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.502667836.00000000067C0000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x9a8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x34e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6028:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8b70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xb6b8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xe200:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x10d48:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x138a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x163f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18f50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1baa8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1e600:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x21168:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x23cd0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x26838:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x293a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2bf08:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2ea70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x315e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.502479061.0000000006841000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x8f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x34b8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6080:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8c48:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xb810:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xe3d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x10fb0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x13b88:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x16760:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x19338:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1bf10:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1eaf8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x216e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x242c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x26eb0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x29a98:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2c690:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2f288:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x31e80:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x34a78:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x37670:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.507423559.0000000005FC0000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xf18:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2fa0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5028:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x70b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9138:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xb1d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xd268:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xf300:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x11398:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x13430:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x154c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x17570:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x19618:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b6c0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1d768:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1f810:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x218c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x23980:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.502365955.00000000067F3000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1160:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3cd8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6850:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x93c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xbf50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xead8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x11660:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x141e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x16d70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x198f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1c480:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1f018:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x21bb0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x24748:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x272e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x29e78:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2ca20:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2f5c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x32170:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x34d18:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x378c0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499804770.0000000006E61000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x210:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.508327386.0000000005DBE000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1010:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2da8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.508977198.0000000005C2E000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xaa8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x25a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x4098:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5ba0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x76a8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x91b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xacb8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xc7c0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xe2c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xfde0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.508083711.0000000005EC0000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x8d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.507943546.0000000005E86000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xa60:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2918:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x47d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6688:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8540:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xa408:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xc2d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xe198:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x10060:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x11f28:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x13df0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15cc8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x17ba0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x19a78:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b950:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1d838:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1f720:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x21608:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x234f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x253d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x272c0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500124456.0000000006E24000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x2780:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499664750.0000000006E74000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xc30:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.507900626.0000000005F40000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x3f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.502171014.0000000006880000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xa78:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3680:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6288:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8e90:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xbaa8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xe6c0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x112d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x13ef0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x16b08:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x19720:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1c348:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1ef70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x21b98:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x247c0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x273e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2a020:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2cc58:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2f890:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x324c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x35110:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x37d58:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.501943577.0000000006902000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xcf0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3988:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6620:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x92b8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xbf50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xebf8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x118a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x14548:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x171f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x19e98:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1cb40:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1f7f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x224b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x25168:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x27e20:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2aad8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2d7a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x30468:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x33130:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x35df8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x38ac0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499900664.0000000006E4A000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x448:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.501775845.00000000069FF000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1520:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x42a8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7040:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9dd8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xcb70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xf908:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x126a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15448:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x181f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1af98:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1dd40:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x20ae8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.507263765.000000000606A000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x12b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3418:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5580:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x76e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.505360761.00000000063EC000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1428:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3a40:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6058:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8680:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xaca8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xd2d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xf8f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x11f20:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x14558:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x16b90:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x191c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b800:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1de48:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x20490:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x22ad8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x25120:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x27778:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x29dd0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2c428:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2ea80:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x310e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000009.00000002.556829484.0000000000F58000.00000004.00000020.00020000.00000000.sdmp | SUSP_PS1_Msdt_Execution_May22 | Detects suspicious calls of msdt.exe as seen in CVE-2022-30190 / Follina exploitation | Nasreddine Bencherchali, Christian Burkard | - 0x9886:$a: PCWDiagnostic
- 0x15de4:$a: PCWDiagnostic
- 0x2e7c:$sa1: msdt.exe
- 0x8bb0:$sa1: msdt.exe
- 0x18b6e:$sa1: msdt.exe
- 0x193f2:$sb3: IT_BrowseForFile=
|
00000019.00000003.506426333.000000000626E000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x16e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3af8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5f10:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8328:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xa740:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xcb58:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xef70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x11388:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x137b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15bd8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18000:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1a428:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1c850:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1ec78:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x210b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x234e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x25920:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x27d58:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2a190:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2c5d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2ea20:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500371775.0000000006DEB000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x15a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.509507876.0000000005B3D000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x8c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2210:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3b68:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000002.568633989.0000000006E16000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x438:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500271247.0000000006E01000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1e48:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.509762082.0000000005B40000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xb68:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000002.568691207.0000000006E29000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xb78:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.507305461.0000000005FE5000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xa38:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2af0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x4ba8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6c60:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8d28:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xadf0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xdec0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xff88:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12050:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x14118:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x161e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x182b8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1a390:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1c468:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1e540:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x20618:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x22700:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x247e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x268d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x289b8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2aaa0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500574937.0000000006DC3000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x2ec0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500300611.0000000006DF8000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1390:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500381322.0000000006DE8000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1238:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499851554.0000000006E57000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x538:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000002.568719259.0000000006E33000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x770:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3b78:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.504543226.0000000006527000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xbc0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x33a8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5b90:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8388:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xab80:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xd378:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xfb70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12378:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x14b80:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x17388:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x19b90:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1c398:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1ebb0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x213c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x23be0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x263f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x28c10:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2b438:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2dc60:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x30488:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x32cb0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000002.569049205.0000000006E9D000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x2878:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5d50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9238:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xc720:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xfc08:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x13100:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499716165.0000000006E6A000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xef8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.506765353.0000000006170000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xd58:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3010:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x52c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7580:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9838:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xbb00:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xddc8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x10090:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12358:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x14620:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x168f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18bd0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1aea8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1d180:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.506625375.00000000061EF000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1078:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x33f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5768:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7ae0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9e58:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xc1e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xe568:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x108f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12c78:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15000:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x17388:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x19720:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1bab8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1de50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x201e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x22580:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x24928:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x26cd0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x29078:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2b420:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2d7c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.509636935.0000000005B40000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xb68:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.508201854.0000000005DC2000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xb40:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x28d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x4670:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6408:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x81b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9f58:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xbd00:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xdaa8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xf850:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x115f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x133b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15168:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x16f20:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18cd8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1aa90:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1c848:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1e610:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x203d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x221a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x23f68:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x25d30:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.501854915.0000000006980000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xe18:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3b30:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6848:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9560:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xc278:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xef90:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x11cb8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x149e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x17708:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1a430:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1d158:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1fe80:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x22bb8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x258f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x28628:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2b360:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2e098:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x30dd0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x33b08:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x36850:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x39598:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499572225.0000000006E8B000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xbf8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500537921.0000000006DCC000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x4f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500290954.0000000006DFB000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1718:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.509363516.0000000005B41000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x14c0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2e18:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x4770:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x60c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7a30:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9398:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xad00:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xc668:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xdfd0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xf948:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x112c0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12c38:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x145b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15f28:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x178a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x19228:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1abb0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1c538:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1dec0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1f848:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x211e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499838198.0000000006E5A000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x980:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499586408.0000000006E87000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1750:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.509707518.0000000005B40000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xb68:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.508774998.0000000005C75000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1588:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x30f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x4c58:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x67d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8348:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9ec0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xba38:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xd5b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xf128:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x10cb0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12838:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x143c0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15f48:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x17ad0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x19668:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b200:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1cd98:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1e930:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x204c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x22070:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x23c18:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.504055585.00000000065C0000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xf08:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x37c0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6078:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8940:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xb208:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xdad0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x10398:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12c70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15548:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x17e20:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1a6f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1cfe0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1f8c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x221b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x24a98:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x27380:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x29c68:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2c560:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2ee58:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x31750:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x34048:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.508725411.0000000005CBA000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1758:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3340:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x4f28:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500355385.0000000006DEE000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1918:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499979043.0000000006E3A000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x33a8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000002.568622396.0000000006E13000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x80:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500225710.0000000006E0E000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1cc8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.506934087.00000000060F7000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1858:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3a70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5c88:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7ea0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xa0c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xc2f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xe518:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x10740:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12968:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x14b90:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x16dc8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x19000:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b238:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1d470:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1f6a8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x218e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x23b18:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x25d60:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x27fa8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2a1f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2c438:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.506382622.00000000062DB000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1620:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3ab8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5f50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x83e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xa880:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xcd28:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xf1d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x11678:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500146207.0000000006E1E000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1fb0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.503951630.0000000006608000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x8c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x31e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5b08:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8430:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xad58:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xd680:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xffa8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x128e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15218:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x17b50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1a488:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1cdc0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1f6f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x22040:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x24988:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x272d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x29c18:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2c560:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2eeb8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x31810:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x34168:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500435591.0000000006DDC000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x4e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500214700.0000000006E11000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x2080:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.509015844.0000000005BEC000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1730:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x31b8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x4c40:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x66c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8160:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9bf8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xb690:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xd128:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xebc0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x10668:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12110:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x13bb8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15660:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x17108:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18bb0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1a668:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1c120:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1dbd8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1f690:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x21158:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x22c20:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.499330598.0000000006CBF000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xba0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3c88:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6d70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9e58:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xcf50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x10048:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x13140:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x16248:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x19360:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1c478:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1f5a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x226c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x257f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x28928:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2ba60:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2eb98:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x31ce0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x34e38:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x37f90:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3b0e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3e250:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.505281515.0000000006456000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xe18:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x34d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5b98:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8260:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xa928:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xcff0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xf6c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x11da0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x14478:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.508508228.0000000005D3A000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xc78:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2930:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x45e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x62a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7f58:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9c20:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xb8e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xd5b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xf278:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x10f50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12c28:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x14900:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x165d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x182c0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x19fa8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1bc90:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1d978:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1f660:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x21358:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x23050:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x24d48:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.507143214.0000000006072000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1850:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x39c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5b40:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7cb8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9e30:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xbfb8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xe140:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x102c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12450:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x145d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x16760:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x188f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1aa90:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1cc28:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1edc0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x20f58:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x230f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x25298:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x27440:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x295e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2b790:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.509189150.0000000005BB0000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x13c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2de0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x47f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7228:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8c50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xa678:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xc0a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xdac8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xf500:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.507585756.0000000005F67000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1288:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3290:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5298:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x72b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x92c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xb2e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xd2f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xf310:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x11328:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x13350:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15378:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x173a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x193c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b3f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1d428:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1f460:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x21498:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x234d0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x25508:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x27550:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x29598:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.501274310.0000000006AFF000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1608:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x4490:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7318:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xa1a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xd038:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xfed0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12d68:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15c00:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18a98:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b940:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1e7e8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x21690:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x24538:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x273e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2a288:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2d140:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2fff8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x32eb0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x35d68:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x38c20:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3bad8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.508358895.0000000005D63000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1450:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3158:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x4e60:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6b78:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8890:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xa5a8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xc2c0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xdfd8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xfd00:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x11a28:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x13750:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15478:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x171a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18ed8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1ac10:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1c948:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1e680:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x203b8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x220f0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x23e28:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x25b70:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.508666437.0000000005CC0000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0xb10:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x26f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x42e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x5ed8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7ad0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x96c8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xb2c0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xcec8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xead0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x106d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x122e0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x13ee8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15af0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x176f8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x19310:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1af28:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1cb40:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1e758:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x20370:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x21f98:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x23bc0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.500854607.0000000006B80000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1008:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3f10:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x6e18:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x9d20:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xcc28:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xfb30:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x12a38:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x15950:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x18868:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1b780:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1e698:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x215b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x244d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x27400:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2a328:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2d250:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x30178:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x330a0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x35fd8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x38f10:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3be48:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
00000019.00000003.498808453.0000000006D3A000.00000004.00000800.00020000.00000000.sdmp | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x1340:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x4528:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x7710:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xa908:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xdb10:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x10d18:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x13f20:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x17138:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1a360:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1d588:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x207b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x239d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x26c10:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x29e48:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2d090:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x302d8:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x33520:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x36768:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x399b0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3cc08:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3fe60:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
Process Memory Space: msdt.exe PID: 7052 | SUSP_PS1_Msdt_Execution_May22 | Detects suspicious calls of msdt.exe as seen in CVE-2022-30190 / Follina exploitation | Nasreddine Bencherchali, Christian Burkard | - 0x15732:$a: PCWDiagnostic
- 0x33ef6:$a: PCWDiagnostic
- 0x5be2:$sa1: msdt.exe
- 0x8b98:$sa1: msdt.exe
- 0x1713c:$sa1: msdt.exe
- 0x23b20:$sa1: msdt.exe
- 0x26ad6:$sa1: msdt.exe
- 0x2d3dc:$sa1: msdt.exe
- 0x30392:$sa1: msdt.exe
- 0x33ec3:$sa1: msdt.exe
- 0x33ee0:$sa1: msdt.exe
- 0x340ec:$sa1: msdt.exe
- 0x37d6c:$sa1: msdt.exe
- 0x37d74:$sa1: msdt.exe
- 0x37d7c:$sa1: msdt.exe
- 0x3a540:$sa1: msdt.exe
- 0x3e689:$sa1: msdt.exe
- 0x33f49:$sb3: IT_BrowseForFile=
|
Process Memory Space: mshta.exe PID: 5852 | Cobaltbaltstrike_Payload_Encoded | Detects CobaltStrike payloads | Avast Threat Intel Team | - 0x13cd:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1cfc:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x8f7d:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xb309:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0xbad0:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x13f7b:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x16888:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1ee1f:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x1faa3:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x24fab:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2bf06:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x2dc50:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x31455:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x32c23:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x371c5:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3b700:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x3ce8c:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x45afa:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x46a3d:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x48e17:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
- 0x4c3bb:$s17: Array(-4,-24,-119,0,0,0,96,-119,-27,49,-46,100,-117,82,48,-117
|
Click to see the 170 entries |