Post

Log inSign up

Post

user avatar
Unit 42
@Unit42_Intel
2023-02-24 (Friday): #IcedID (#Bokbot) --> #BackConnect on 135.148.217[.]85:8080 --> #CobaltStrike on 23.227.203[.]70:80/aspnetcenter[.]com - IoCs available at bit.ly/3J7r51f - Thanks to @drb_ra, @teamcymru_S2 & @pr0xylife for previous tweets related to this activity!
Wireshark pcap showing IcedID installer retrieving Gzip binary, IcedID C2 traffic, IcedID BackConnect traffic, and where Cobalt Strike traffic starts
IcedID BackConnect Traffic
IcedID BackConnect Traffic, Command for Cobalt Strike
IcedID BackConnect Traffic
5:55 PM · Feb 27, 202311.7KViews

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Relevant people

user avatar
Unit 42@Unit42_IntelFollow

Trending now

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up