Hermes CTI

← Back to all reports

malware-campaign updated

Gootloader campaign uses SEO poisoning, Cobalt Strike, and SystemBC

● HIGH Confidence: 90% · Version 2

Executive summary

Observed behavior included JavaScript execution, obfuscated PowerShell, scheduled-task and registry-run-key persistence, payloads stored in registry and loaded in memory, process injection, SMB/WMI/remote-service activity, RDP tunneled through SystemBC, WinRM, and discovery of domain and file-share information. The report identifies Cobalt Strike at 91.215.85.143:443 and SystemBC at 91.92.136.20:4001.

Technical analysis

Observed behavior included JavaScript execution, obfuscated PowerShell, scheduled-task and registry-run-key persistence, payloads stored in registry and loaded in memory, process injection, SMB/WMI/remote-service activity, RDP tunneled through SystemBC, WinRM, and discovery of domain and file-share information. The report identifies Cobalt Strike at 91.215.85.143:443 and SystemBC at 91.92.136.20:4001.

Evidence and sources

The DFIR Report published on 2024-02-26 describes a Gootloader campaign using SEO poisoning, a deceptive ZIP/JavaScript execution chain, Cobalt Strike, and SystemBC. The report documents PowerShell, scheduled-task logon persistence, registry-stored payloads, process injection, SMB remote services, WMI, RDP tunneling, WinRM, and discovery activity. The report lists Cobalt Strike 91.215.85[.]143:443, SystemBC 91.92.136[.]20:4001, ten xmlrpc.php URLs, and MD5/SHA1/SHA256 hashes for the observed ZIP, JavaScript, DLL, EXE and beacon files. The DFIR Report links its public Case 19530 YARA rule set, which contains file names, hashes, PE conditions, and distinctive strings for the observed Gootloader, SystemBC, and Cobalt Strike artifacts.

Verified Evidence Claims

The DFIR Report published on 2024-02-26 describes a Gootloader campaign using SEO poisoning, a deceptive ZIP/JavaScript execution chain, Cobalt Strike, and SystemBC.

Attribution: The DFIR Report
95% Confidence Analysis 🔍

The report documents PowerShell, scheduled-task logon persistence, registry-stored payloads, process injection, SMB remote services, WMI, RDP tunneling, WinRM, and discovery activity.

Attribution: The DFIR Report
95% Confidence Analysis 🔍

The report lists Cobalt Strike 91.215.85[.]143:443, SystemBC 91.92.136[.]20:4001, ten xmlrpc.php URLs, and MD5/SHA1/SHA256 hashes for the observed ZIP, JavaScript, DLL, EXE and beacon files.

Attribution: The DFIR Report
95% Confidence Analysis 🔍

The DFIR Report links its public Case 19530 YARA rule set, which contains file names, hashes, PE conditions, and distinctive strings for the observed Gootloader, SystemBC, and Cobalt Strike artifacts.

Attribution: The DFIR Report
95% Confidence Analysis 🔍

IOCs

CVEs and affected products

No CVE or affected product is available.

ATT&CK mapping

Drive-by Compromise

Tactic: initial-access

Malicious File

Tactic: execution

PowerShell

Tactic: execution

Scheduled Task/Job: Scheduled Task

Tactic: persistence

Registry Run Keys / Startup Folder

Tactic: persistence

Obfuscated Files or Information

Tactic: defense-evasion

Process Injection

Tactic: defense-evasion

Windows Management Instrumentation

Tactic: execution

Remote Services: Remote Desktop Protocol

Tactic: lateral-movement

Windows Remote Management

Tactic: lateral-movement

Ingress Tool Transfer

Tactic: command-and-control

Web Protocols

Tactic: command-and-control

Remote System Discovery

Tactic: discovery

Domain Account

Tactic: discovery

Detection content

Sigma rules, YARA rules, Splunk SPL, and KQL detection logic.

Open dedicated detections page →

Threat hunting

Hypothesis-driven hunt procedures and telemetry checklist.

Open dedicated hunt page →

Remediation

Containment actions, patching notes, and credential steps.

Open dedicated remediation page →

Historical relationships

No published historical relationship is available.

Timeline and change history

Intrusion activity: The source reports the intrusion began in February 2023.
Public report: The DFIR Report published the public case report.

Confidence and caveats

0.9

⚠️ This is public CTI only and does not assess any organization’s exposure.

⚠️ The source could not confirm data exfiltration.

⚠️ The two requested URLs returned HTTP 404 and are not represented as ingested evidence.