CobaltStrike_Resources_Httpstager64_Bin_v3_2_through_v4_x
Description
Cobalt Strike's resources/httpstager64.bin signature for versions v3.2 to v4.x
Query · yara
strings:
/*
48 31 C0 xor rax, rax
AC lodsb
41 C1 C9 0D ror r9d, 0Dh
41 01 C1 add r9d, eax
38 E0 cmp al, ah
75 F1 jnz short loc_100000000000007D
4C 03 4C 24 08 add r9, [rsp+40h+var_38]
45 39 D1 cmp r9d, r10d
75 D8 jnz short loc_100000000000006E
58 pop rax
44 8B 40 24 mov r8d, [rax+24h]
49 01 D0 add r8, rdx
66 41 8B 0C 48 mov cx, [r8+rcx*2]
44 8B 40 1C mov r8d, [rax+1Ch]
49 01 D0 add r8, rdx
41 8B 04 88 mov eax, [r8+rcx*4]
48 01 D0 add rax, rdx
*/
$apiLocator = {
48 [2]
AC
41 [2] 0D
41 [2]
38 ??
75 ??
4C [4]
45 [2]
75 ??
5?
44 [2] 24
49 [2]
66 [4]
44 [2] 1C
49 [2]
41 [3]
48
}
// the signature for httpstager64 and httpsstager64 really the inclusion or exclusion of InternetSetOptionA. However,
// there is a subtle difference in the jmp after the InternetOpenA call (short jmp for x86 and long jmp for x64)
/*
41 BA 3A 56 79 A7 mov r10d, InternetOpenA
FF D5 call rbp
EB 61 jmp short j_get_c2_ip
*/
$postInternetOpenJmp = {
41 ?? 3A 56 79 A7
FF ??
EB
}
condition:
$apiLocator and $postInternetOpenJmp