MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4b459c85c8425e368325d8844148e6a058d350374eb721a3da26c4e85ba26973. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CobaltStrike


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 4b459c85c8425e368325d8844148e6a058d350374eb721a3da26c4e85ba26973
SHA3-384 hash: fbc1129e51e570728e4167519b47d3a0839ae1dfee401256c45004015fcf4a8d3512cef3b87abddd9346e9d4d5305eb6
SHA1 hash: a1f4970ee17255e5ad5fbf9df5041211b54df2d1
MD5 hash: 934078e7de60e4683f046a060ba0afa6
humanhash: william-quebec-nebraska-diet
File name:4b459c85c8425e368325d8844148e6a058d350374eb721a3da26c4e85ba26973
Download: download sample
Signature CobaltStrike
File size:179'200 bytes
First seen:2020-09-08 11:44:16 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash aa80902f3bdba6e23f58616933e9dfbe (1 x CobaltStrike)
ssdeep 3072:xrnso5IdgW1CUf8rgtBf1YpMwQuY2BQ/:xDF5IdgW1Csvg6
TLSH 13044B00B9E94031F9F3463F86BC9E5115BE7D254F6A9ACF6AC80CCD82785D26335B62
Reporter JAMESWT_WT
Tags:CobaltStrike

Intelligence


File Origin
# of uploads :
1
# of downloads :
104
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending an HTTP GET request
Threat name:
Win32.Trojan.Swrort
Status:
Malicious
First seen:
2020-09-01 16:25:00 UTC
File Type:
PE (Exe)
Extracted files:
1
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
n/a
Behaviour
Modifies data under HKEY_USERS
Suspicious use of AdjustPrivilegeToken
Drops file in Windows directory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments