MalwareBazaar Database

This page shows some basic information the YARA rule HKTL_CobaltStrike_Beacon_XOR_Strings including corresponding malware samples.

Database Entry


YARA Rule:HKTL_CobaltStrike_Beacon_XOR_Strings
Author:Elastic
Description:Identifies XOR'd strings used in Cobalt Strike Beacon DLL
Firstseen:2021-10-15 22:25:16 UTC
Lastseen:2026-03-18 09:03:24 UTC
Sightings:18

Malware Samples


The table below shows all malware samples that matching this particular YARA rule (max 1000).

Firstseen (UTC)SHA256 hashTagsSignatureReporter