Posh C2 Detected - 91[.]215[.]85[.]39:443 - RedPacket Security

Posh C2 Detection Alerts

RedPacket Security
Posh C2 Detected - 52[.]74[.]99[.]87:443 - RedPacket Security

Posh C2 Detection Alerts

RedPacket Security
Posh C2 Detected - 3[.]144[.]92[.]52:443 - RedPacket Security

Posh C2 Detection Alerts

RedPacket Security
Posh C2 Detected - 3[.]145[.]34[.]133:443 - RedPacket Security

Posh C2 Detection Alerts

RedPacket Security
Posh C2 Detected - 185[.]147[.]124[.]108:443 - RedPacket Security

Posh C2 Detection Alerts

RedPacket Security
Posh C2 Detected - 185[.]147[.]124[.]10:443 - RedPacket Security

Posh C2 Detection Alerts

RedPacket Security
Posh C2 Detected - 185[.]147[.]124[.]104:443 - RedPacket Security

Posh C2 Detection Alerts

RedPacket Security
Posh C2 Detected - 176[.]111[.]174[.]138:443 - RedPacket Security

Posh C2 Detection Alerts

RedPacket Security
Posh C2 Detected - 3[.]109[.]173[.]1:443 - RedPacket Security

Posh C2 Detection Alerts

RedPacket Security
Threat Actors’ Toolkit: Leveraging Sliver, PoshC2 & Batch Scripts

Key Takeaways In early December of 2023, we discovered an open directory filled with batch scripts, primarily designed for defense evasion and executing command and control payloads. These scripts …

The DFIR Report