Gootloader campaign uses SEO poisoning, Cobalt Strike, and SystemBC
Executive summary
Observed behavior included JavaScript execution, obfuscated PowerShell, scheduled-task and registry-run-key persistence, payloads stored in registry and loaded in memory, process injection, SMB/WMI/remote-service activity, RDP tunneled through SystemBC, WinRM, and discovery of domain and file-share information. The report identifies Cobalt Strike at 91.215.85.143:443 and SystemBC at 91.92.136.20:4001.
Technical analysis
Observed behavior included JavaScript execution, obfuscated PowerShell, scheduled-task and registry-run-key persistence, payloads stored in registry and loaded in memory, process injection, SMB/WMI/remote-service activity, RDP tunneled through SystemBC, WinRM, and discovery of domain and file-share information. The report identifies Cobalt Strike at 91.215.85.143:443 and SystemBC at 91.92.136.20:4001.
Evidence and sources
The DFIR Report published on 2024-02-26 describes a Gootloader campaign using SEO poisoning, a deceptive ZIP/JavaScript execution chain, Cobalt Strike, and SystemBC. The report documents PowerShell, scheduled-task logon persistence, registry-stored payloads, process injection, SMB remote services, WMI, RDP tunneling, WinRM, and discovery activity. The report lists Cobalt Strike 91.215.85[.]143:443, SystemBC 91.92.136[.]20:4001, ten xmlrpc.php URLs, and MD5/SHA1/SHA256 hashes for the observed ZIP, JavaScript, DLL, EXE and beacon files. The DFIR Report links its public Case 19530 YARA rule set, which contains file names, hashes, PE conditions, and distinctive strings for the observed Gootloader, SystemBC, and Cobalt Strike artifacts.
The DFIR Report published on 2024-02-26 describes a Gootloader campaign using SEO poisoning, a deceptive ZIP/JavaScript execution chain, Cobalt Strike, and SystemBC.
The report documents PowerShell, scheduled-task logon persistence, registry-stored payloads, process injection, SMB remote services, WMI, RDP tunneling, WinRM, and discovery activity.
The report lists Cobalt Strike 91.215.85[.]143:443, SystemBC 91.92.136[.]20:4001, ten xmlrpc.php URLs, and MD5/SHA1/SHA256 hashes for the observed ZIP, JavaScript, DLL, EXE and beacon files.
The DFIR Report links its public Case 19530 YARA rule set, which contains file names, hashes, PE conditions, and distinctive strings for the observed Gootloader, SystemBC, and Cobalt Strike artifacts.
IOCs
91.215.85.143
91.92.136.20
https://hrclubphilippines.com/xmlrpc.php
https://my-little-kitchen.com/xmlrpc.php
https://pocketofpreschool.com/xmlrpc.php
fb6e4f75763fad6d0e7fe85a563b0c24
7e8543f2bc09bf320510fde5e34e32065339d9d2
873dd1dcdfcbe982a8f15539a41f48166873eab3feb55fb1104202e4152bd507
deb24dfaf8178fda2d070aba9134a30c
ecc0b26106703e129fb1e2ec132c373870c2e7b6
f94048917ac75709452040754bb3d1a0aff919f7c2b4b42c5163c7bdb1fbf346
25b38e45df3cd215386077850c59be07
a88a28c73aa42956c9f9d12585a8de63d4a00e47
68dd1a2da732d56b0618f8581502fcf209b1c828c97d05f239c98d55bb78b562
1b8b4f05058ac39091b99cc153ab00c0
e0b568a3e35257cd30b0c42727c3529cef13b081
831955bd05186381a8f15539a41f48166873eab3feb55fb1104202e4152bd507
9f9c7b2c8f245e62a08bf5f8a3eb3498
3cf851eb09c934cafe9b98d4706f903dff804b0c
aad75498679aada9ee2179a8824291e3b4781d5683c2fa5b3ec92267ce4a4a33
CVEs and affected products
No CVE or affected product is available.
ATT&CK mapping
Drive-by Compromise
Tactic: initial-access
Malicious File
Tactic: execution
PowerShell
Tactic: execution
Scheduled Task/Job: Scheduled Task
Tactic: persistence
Registry Run Keys / Startup Folder
Tactic: persistence
Obfuscated Files or Information
Tactic: defense-evasion
Process Injection
Tactic: defense-evasion
Windows Management Instrumentation
Tactic: execution
Remote Services: Remote Desktop Protocol
Tactic: lateral-movement
Windows Remote Management
Tactic: lateral-movement
Ingress Tool Transfer
Tactic: command-and-control
Web Protocols
Tactic: command-and-control
Remote System Discovery
Tactic: discovery
Domain Account
Tactic: discovery
Detection content
Sigma rules, YARA rules, Splunk SPL, and KQL detection logic.
Threat hunting
Hypothesis-driven hunt procedures and telemetry checklist.
Remediation
Containment actions, patching notes, and credential steps.
Historical relationships
No published historical relationship is available.
Timeline and change history
Confidence and caveats
0.9
⚠️ This is public CTI only and does not assess any organization’s exposure.
⚠️ The source could not confirm data exfiltration.
⚠️ The two requested URLs returned HTTP 404 and are not represented as ingested evidence.