Stats
- First seen
- July 2024
- Last seen
- July 2024
Description
Detects HTTP responses with the fixed JSON structure of the CSBundle Cobalt Strike Malleable C2 profile, in the variant that disguises the command and control server as a Microsoft Office update service. The identical response body across connections is a strong indicator of an infected client beaconing to its operator.
No cross-references or related blog posts found for this signature.