ET Threatview.io High Confidence Cobalt Strike C2 IP group 20
Sourceet/open
CreatedDecember 9, 2021
UpdatedMay 29, 2026
Classificationmisc-attack
alert ip [139.60.161.45,139.60.161.57,172.104.232.196,164.90.153.100,3.13.144.126,143.198.190.57,45.142.122.59,78.128.112.199,143.198.150.148,5.39.222.151,185.150.117.189,139.60.161.69,31.7.62.24,139.60.161.47,3.20.104.56,18.217.66.68,167.99.80.207,3.20.104.56,80.249.144.233,147.182.220.15,149.56.127.166,216.244.71.155,84.38.182.248,80.249.144.233,80.249.145.212,77.223.99.210,216.244.71.155,5.101.50.140,164.90.154.97,149.56.127.166,147.182.220.15,167.172.136.160,146.0.77.18,5.39.223.131,66.42.33.159,54.196.7.25,143.198.150.148,23.227.198.246,3.13.144.126,194.37.97.153,217.79.243.148,149.255.35.131,193.201.9.229,185.150.119.157,185.70.184.2,172.96.189.218,23.224.152.138,185.244.150.102,172.96.189.218,23.227.198.246] any -> $HOME_NET any (msg:"ET Threatview.io High Confidence Cobalt Strike C2 IP group 20"; reference:url,threatview.io/Downloads/High-Confidence-CobaltStrike-C2%20-Feeds.txt; threshold:type limit, track by_src, seconds 3600, count 1; classtype:misc-attack; sid:2527019; rev:1621; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag Threatview_CS, signature_severity Major, created_at 2021_12_09, updated_at 2026_05_29;)
Metadata
affected productAny
attack targetAny
deploymentPerimeter
tagThreatview_CS
signature severityMajor
created at2021_12_09
updated at2026_05_29
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!