{"protocol":"https","settings":{"SETTING_C2_CHUNK_POST":0,"SETTING_C2_POSTREQ":[["_HEADER","Content-Type: application/octet-stream"],["BUILD","id"],["PARAMETER","id"],["BUILD","output"],["PRINT",true]],"SETTING_C2_RECOVER":[["print",true]],"SETTING_C2_REQUEST":[["BUILD","metadata"],["BASE64",true],["HEADER","Cookie"]],"SETTING_C2_VERB_GET":"GET","SETTING_C2_VERB_POST":"POST","SETTING_CFG_CAUTION":0,"SETTING_CLEANUP":0,"SETTING_CRYPTO_SCHEME":0,"SETTING_DNS_IDLE":"0.0.0.0","SETTING_DNS_SLEEP":0,"SETTING_DOMAINS":"39.109.117.51,/pixel.gif","SETTING_GARGLE_NOOK":0,"SETTING_JITTER":0,"SETTING_KILLDATE":0,"SETTING_MAXDNS":255,"SETTING_MAXGET":1048576,"SETTING_PIPENAME":"","SETTING_PORT":443,"SETTING_PROCINJ_BOF_REUSE_MEM":5,"SETTING_PROCINJ_MINALLOC":0,"SETTING_PROCINJ_PERMS":64,"SETTING_PROCINJ_PERMS_I":64,"SETTING_PROCINJ_TRANSFORM_X64":[["append",""],["prepend",""]],"SETTING_PROCINJ_TRANSFORM_X86":[["append",""],["prepend",""]],"SETTING_PROTOCOL":8,"SETTING_PROXY_BEHAVIOR":2,"SETTING_PUBKEY":"bcf21d0f5da553af114b2555c6ed7c14eddd04aea263eb81efe02dfab3b621b3","SETTING_SLEEPTIME":60000,"SETTING_SPAWNTO_X64":"%windir%\\sysnative\\rundll32.exe","SETTING_SPAWNTO_X86":"%windir%\\syswow64\\rundll32.exe","SETTING_SUBMITURI":"/submit.php","SETTING_USERAGENT":"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322)","SETTING_WATERMARK":0},"trial":false,"version":"Cobalt Strike 3.13 (Jan 02, 2019)","watermark":0}
