Mapping and Pivoting from Cobalt Strike C2 Infrastructure Attributed to CVE-2021-40444

Michael Koczwara
11 min readSep 12, 2021
  • Threat Actors Infrastructure (VT Analysis).
  • Pivoting from 45.147.229[.]242
  • Pivoting from 104.194.10[.]21
  • Pivoting from 45.153.240[.]220
  • Short summary and IOC’s.
Threat Actors Cobalt Strike C2 Infrastructure