Monitoring Threat Actors Cobalt Strike C2 Infrastructure with Shodan

Michael Koczwara
3 min readSep 21, 2021

Threat Intel Tips and Shodan queries

ReliableSite, Leaseweb, ITL-Bulgaria, and HostKey Infrastructure are good examples but you can also look for and monitor other ISP’s/orgs.

ReliableSite

org:”ReliableSite.Net LLC” port:”443" HTTP/1.1 404 Not Found Content-Length: 0

examples:

Cobalt Strike C2 mubuwu.com
Cobalt Strike C2 dodefoh.com

Leaseweb

isp:”Leaseweb” port:”443" HTTP/1.1 404 Not Found Content-Length: 0 org:”Leaseweb USA, Inc.”

examples:

Cobalt Strike C2 hubojo.com
Cobalt Strike C2 zeheza.com

ITL-Bulgaria Ltd

isp:”ITL-Bulgaria Ltd.” port:”443" HTTP/1.1 404 Not Found Content-Length: 0

examples:

Cobalt Strike C2 travelnumb.com

Hostkey

isp:”hostkey” port:”443" HTTP/1.1 404 Not Found Content-Length: 0

--

--