GENERAL__2021__Tracking_Cobalt_Strike_A_Trend_Micro_Vision_One_Investigation.pdf
ID: 96c8e2bb-8799-4bc9-8a41-7d900def57fd
STIX ID: report--96c8e2bb-8799-4bc9-8a41-7d900def57fd
Threat Score
82/100
Uploaded: 2026-08-19
Published Date: 2021-07-09
Last Modified Date: 2021-07-09
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro’s Vision One investigation tracks a Cobalt Strike infection across multiple endpoints, detailing file downloads (including iroto.tio and l9c4b8e.exe), process hijacking (rundll32.exe), IOC/TP detections, suspected ransomware toolkits, and pass-the-hash activity. The report maps the attack chain from initial spear-phishing to lateral movement and containment steps, highlighting multi-endpoint exposure and recommended remediation and monitoring.
