216.73.216.6

Malicious Campaign Analysis: JScript RAT and CobaltStrike

· Published 07/06/2024 08:59 · Modified 07/06/2024 09:37

Export JSON

Essential information

Published
07/06/2024 08:59
Modified
07/06/2024 09:37
Tags
2024-06-07 cobaltstrike encryption jscript jscript rat obfuscation rat
Related entities
4 observables, 9 techniques (mitre), 1 malware

Description

This report examines a recent malicious campaign involving a -based Remote Access Trojan () and its connections to the penetration testing tool. The attack commences with an obfuscated loader distributed through suspected phishing campaigns. Upon execution, it contacts a command and control (C&C) server to retrieve a second-stage loader. This loader employs WinHttpRequest and RC4 to obtain the main component, a -based malware that maintains persistent communication with the C&C for receiving additional instructions. The report provides technical analysis of the malware components and speculates on potential connections to simulated attacks or threat actor testing based on observed IP ranges.

External references