diff --git a/2019/08/2019-08-05-CobaltStrike.md b/2019/08/2019-08-05-CobaltStrike.md new file mode 100644 index 000000000..1c8b03c93 --- /dev/null +++ b/2019/08/2019-08-05-CobaltStrike.md @@ -0,0 +1,136 @@ +**Are you the copyright owner or authorized to act on the copyright +owner’s behalf?** + +Yes. Strategic Cyber LLC is the copyright owner. I am [private] of +Strategic Cyber LLC. + +**Please provide a detailed description of the original copyrighted +work that has allegedly been infringed. If possible, include a URL to +where it is posted online.** + +The infringed work is Cobalt Strike, a commercial software platform +for Adversary Simulations and Red Team Operations. + +https://www.cobaltstrike.com/ + +SHA-256 hashes for the licensed Cobalt Strike product and its trial +archives are published at: + +[private] + +**What files should be taken down? Please provide URLs for each file, +or if the entire repository, the repository’s URL:** + +The following repository contains cracked versions of the Cobalt +Strike 3.13 and 3.14 trial packages: + +https://github.com/sobinge/CobaltStrike + +The following repository contains a cracked version of the Cobalt +Strike 3.14 licensed product, a cracked version of the 3.12 trial +product, and a cracked version of the 3.8 product: + +https://github.com/LangziFun/Security_Codes/ + +Cobalt Strike 3.14 licensed (cracked) +https://github.com/LangziFun/Security_Codes/tree/master/Github%E8%84%9A%E6%9C%AC%E5%B7%A5%E5%85%B7/%E5%85%A5%E4%BE%B5%E5%B7%A5%E5%85%B7/cs + +Cobalt Strike 3.12 trial +https://github.com/LangziFun/Security_Codes/tree/70a04f0ab440cbd3861a569884eeb6bfd5afa331/%E8%B5%84%E6%96%99%E6%96%87%E6%A1%A3/%E5%B0%8F%E5%AF%86%E5%9C%88%E6%96%87%E7%AB%A0%5B%E7%BD%91%E4%BC%A0%20%E4%BE%B5%E5%88%A0%5D/%E5%B7%A5%E5%85%B7/Cobaltstrike_3.12%E8%AF%95%E7%94%A8%5B%E6%9C%AA%E5%A4%84%E7%90%86%5D + +Cobalt Strike 3.8 trial +https://github.com/LangziFun/Security_Codes/tree/70a04f0ab440cbd3861a569884eeb6bfd5afa331/%E8%B5%84%E6%96%99%E6%96%87%E6%A1%A3/%E5%B0%8F%E5%AF%86%E5%9C%88%E6%96%87%E7%AB%A0%5B%E7%BD%91%E4%BC%A0%20%E4%BE%B5%E5%88%A0%5D/Cobalt%20strike/CobaltStrike3.8_By_Klion%5B%E6%B7%BB%E5%8A%A0%E9%83%A8%E5%88%86%E4%B8%AD%E6%96%87%E6%94%AF%E6%8C%81%5D/CobaltStrike3.8_By_Klion%5B%E6%B7%BB%E5%8A%A0%E9%83%A8%E5%88%86%E4%B8%AD%E6%96%87%E6%94%AF%E6%8C%81%5D + +This repository has 47 forks. A review of a representative sample of +these forks shows these files are present in the up to date forks: + +https://github.com/1870387/Security_Codes/tree/master/Github%E8%84%9A%E6%9C%AC%E5%B7%A5%E5%85%B7/%E5%85%A5%E4%BE%B5%E5%B7%A5%E5%85%B7/cs +https://github.com/1uanWu/Security_Codes/tree/master/Github%E8%84%9A%E6%9C%AC%E5%B7%A5%E5%85%B7/%E5%85%A5%E4%BE%B5%E5%B7%A5%E5%85%B7/cs +https://github.com/dlwang624/Security_Codes/tree/master/Github%E8%84%9A%E6%9C%AC%E5%B7%A5%E5%85%B7/%E5%85%A5%E4%BE%B5%E5%B7%A5%E5%85%B7/cs +https://github.com/innocabroad/Security_Codes/tree/master/Github%E8%84%9A%E6%9C%AC%E5%B7%A5%E5%85%B7/%E5%85%A5%E4%BE%B5%E5%B7%A5%E5%85%B7/cs +https://github.com/whoiskkk/Security_Codes/tree/master/Github%E8%84%9A%E6%9C%AC%E5%B7%A5%E5%85%B7/%E5%85%A5%E4%BE%B5%E5%B7%A5%E5%85%B7/cs +https://github.com/lrxcy/Security_Codes/tree/master/Github%E8%84%9A%E6%9C%AC%E5%B7%A5%E5%85%B7/%E5%85%A5%E4%BE%B5%E5%B7%A5%E5%85%B7/cs +https://github.com/markdeng206/Security_Codes/tree/master/Github%E8%84%9A%E6%9C%AC%E5%B7%A5%E5%85%B7/%E5%85%A5%E4%BE%B5%E5%B7%A5%E5%85%B7/cs + +The following repository contains Cobalt Strike 3.8: + +https://github.com/fix-you/unc1e_web_note/blob/master/tools/cobaltstrike(1).jar +https://github.com/fix-you/unc1e_web_note/blob/master/tools/cobaltstrike3.8(Va1n3R%2Bversion)(1).zip + +The following repositories contain the Cobalt Strike 3.12 trial: + +https://github.com/VegyChick/jspbd/blob/master/cobaltstrike.jar +https://github.com/LiYanVip/jspbd/blob/master/cobaltstrike.jar + +**Have you searched for any forks of the allegedly infringing files or +repositories? Each fork is a distinct repository and must be +identified separately if you believe it is infringing and wish to have +it taken down.** + +Yes. Other forks may have appeared since this notice was received/processed. + +**Is the work licensed under an open source license? If so, which open +source license? Are the allegedly infringing files being used under +the open source license, or are they in violation of the license?** + +Cobalt Strike is licensed under the terms of an End User License +Agreement. The terms of this EULA prohibit redistribution without the +express written consent of Strategic Cyber LLC. The terms of this EULA +also prohibit modifications/derivative works. + +https://www.cobaltstrike.com/license + +**What would be the best solution for the alleged infringement? Are +there specific changes the other person can make other than removal?** + +Remove the infringed content. + +**Do you have the alleged infringer’s contact information? If so, +please provide it:** + +No. + +**Type (or copy and paste) the following statement: "I have a good +faith belief that use of the copyrighted materials described above on +the infringing web pages is not authorized by the copyright owner, or +its agent, or the law. I have taken fair use into consideration."** + +I have a good faith belief that use of the copyrighted materials +described above on the infringing web pages is not authorized by the +copyright owner, or its agent, or the law. I have taken fair use into +consideration. + +**Type (or copy and paste) the following statement: "I swear, under +penalty of perjury, that the information in this notification is +accurate and that I am the copyright owner, or am authorized to act on +behalf of the owner, of an exclusive right that is allegedly +infringed."** + +I swear, under penalty of perjury, that the information in this +notification is accurate and that I am the copyright owner, or am +authorized to act on behalf of the owner, of an exclusive right that +is allegedly infringed. + +**Please confirm that you have you have read our Guide to Submitting a +DMCA Takedown Notice: +https://help.github.com/articles/guide-to-submitting-a-dmca-takedown-notice/** + +I have read and understand GitHub's Guide to Filing a DMCA Notice. + +**So that we can get back to you, please provide either your telephone +number or physical address:** + +[private] +Strategic Cyber LLC +1875 Connecticut Ave NW +10th Floor +Washington, DC 20009 + +[private] + +**Please type your full legal name below to sign this request:** + +// signed. + +[private] +