CobaltStrike_Resources_Httpsstager_Bin_v2_5_through_v4_x
Description
Cobalt Strike's resources/httpsstager.bin signature for versions 2.5 to 4.x
Query · yara
strings:
/*
31 ?? xor eax, eax
AC lodsb
C1 ?? 0D ror edi, 0Dh
01 ?? add edi, eax
38 ?? cmp al, ah
75 ?? jnz short loc_10000054
03 [2] add edi, [ebp-8]
3B [2] cmp edi, [ebp+24h]
75 ?? jnz short loc_1000004A
5? pop eax
8B ?? 24 mov ebx, [eax+24h]
01 ?? add ebx, edx
66 8B [2] mov cx, [ebx+ecx*2]
8B ?? 1C mov ebx, [eax+1Ch]
01 ?? add ebx, edx
8B ?? 8B mov eax, [ebx+ecx*4]
01 ?? add eax, edx
89 [3] mov [esp+28h+var_4], eax
5? pop ebx
5? pop ebx
*/
$apiLocator = {
31 ??
AC
C1 ?? 0D
01 ??
38 ??
75 ??
03 [2]
3B [2]
75 ??
5?
8B ?? 24
01 ??
66 8B [2]
8B ?? 1C
01 ??
8B ?? 8B
01 ??
89 [3]
5?
5?
}
// the signature for httpstager and httpsstager really only differ by the flags passed to WinInet API
// and the inclusion of the InternetSetOptionA call. We will trigger off that API
/*
6A 04 push 4
5? push eax
6A 1F push 1Fh
5? push esi
68 75 46 9E 86 push InternetSetOptionA
FF ?? call ebp
*/
$InternetSetOptionA = {
6A 04
5?
6A 1F
5?
68 75 46 9E 86
FF
}
condition:
$apiLocator and $InternetSetOptionA