MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 463218064d1dfba957ebcbb0abb90782106f6e4b173e7b1c207b20a605ebbab9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CobaltStrike


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 463218064d1dfba957ebcbb0abb90782106f6e4b173e7b1c207b20a605ebbab9
SHA3-384 hash: 251e3b04bdafaed282a0e60fb27699e4b57689f4cb72195aeeb40200e1ca53bb71d1b80d361438379634662f11e103c3
SHA1 hash: 8b5620bdac37d12f71ce685225ae5179e6262fb5
MD5 hash: d08e888c104cdd64ccb9a027f880c0a3
humanhash: item-friend-berlin-december
File name:463218064d1dfba957ebcbb0abb90782106f6e4b173e7b1c207b20a605ebbab9
Download: download sample
Signature CobaltStrike
File size:7'165'440 bytes
First seen:2020-09-11 10:04:06 UTC
Last seen:2020-09-11 10:45:07 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 1cd364a9e949d5ecebd6c614e64bc545 (16 x Glupteba, 10 x Snatch, 6 x CobaltStrike)
ssdeep 98304:5bEdS+vuHjYXilREjpD9SGl/itf68nuppQIiz/2B:5bEowOjYXilREjpD9S7yGspdiT2B
Threatray 11 similar samples on MalwareBazaar
TLSH 0E768D03F8A525F9E6FDF13082A193227A7178694332BB935F94566A1A16FD0BF3D301
Reporter JAMESWT_WT
Tags:47.105.143.181 CobaltStrike

Intelligence


File Origin
# of uploads :
2
# of downloads :
113
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Connection attempt
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win64.Trojan.Rozena
Status:
Malicious
First seen:
2020-09-11 10:06:08 UTC
File Type:
PE+ (Exe)
AV detection:
13 of 29 (44.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Behaviour
JavaScript code in executable
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments