Cobalt Strike 操作者在中国、俄罗斯及全球基础设施中利用 PowerShell 加载器
hunt.io | 博客 | #cloud | #c2 | #powershell | #cobalt-strike | #open-directory | #shellcode-loader | #attacker-infrastructure
摘要
研究人员在中国境内服务器开放目录中发现 PowerShell 加载器 y1.ps1:通过反射技术内存执行 shellcode、经百度云函数计算获取二阶段载荷,最终回连俄罗斯境内的 Cobalt Strike Beacon;美、新、港亦有相关 IOC。
- 发布时间
- 收录时间
Skip to content