logo

GENERAL__2021__Tracking_Cobalt_Strike_A_Trend_Micro_Vision_One_Investigation.pdf

ID: 96c8e2bb-8799-4bc9-8a41-7d900def57fd

STIX ID: report--96c8e2bb-8799-4bc9-8a41-7d900def57fd

Threat Score

82/100

Uploaded: 2026-08-19

Published Date: 2021-07-09

Last Modified Date: 2021-07-09

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro’s Vision One investigation tracks a Cobalt Strike infection across multiple endpoints, detailing file downloads (including iroto.tio and l9c4b8e.exe), process hijacking (rundll32.exe), IOC/TP detections, suspected ransomware toolkits, and pass-the-hash activity. The report maps the attack chain from initial spear-phishing to lateral movement and containment steps, highlighting multi-endpoint exposure and recommended remediation and monitoring.