MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 15f237d42968bb43de74e4a164b511efadd9864f5ee94fadbb8fd207dd59eaa5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CobaltStrike


Vendor detections: 13


Intelligence 13 IOCs YARA 23 File information Comments

SHA256 hash: 15f237d42968bb43de74e4a164b511efadd9864f5ee94fadbb8fd207dd59eaa5
SHA3-384 hash: db848d986786bb2e417a8c5162f42685139d26cc5d713bf8c9ebaa6bb2e4cccfa9af8f4a10b2f2f9362ea173aa517b1d
SHA1 hash: b48042611e1249a729315d8047112ec88a311c18
MD5 hash: b3da6f8cfd89a27b1e7346f1d3ccd370
humanhash: rugby-saturn-uranus-colorado
File name:2023-02-09_b3da6f8cfd89a27b1e7346f1d3ccd370_cobaltstrike
Download: download sample
Signature CobaltStrike
File size:212'992 bytes
First seen:2023-02-09 14:31:55 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash c39257d0809c7863eb9636edb4217cc2 (1 x CobaltStrike)
ssdeep 6144:m443XR4SH8CWBeBxi66thkbAzLks1YarGR8ej4rC5Jju:ucLMBIz+YLks1YarGR8PWju
Threatray 167 similar samples on MalwareBazaar
TLSH T15224BF81B41DBF64F14B46BA0E4FF092ADD0B2D6A59EA72B30F5950697CA673300F643
TrID 66.6% (.EXE) DOS Executable Generic (2000/1)
33.3% (.M) Maple Common Binary file (generic) (1001/2)
Reporter petikvx
Tags:Cobalt Strike

Intelligence


File Origin
# of uploads :
1
# of downloads :
112
Origin country :
n/a
Vendor Threat Intelligence
Detection:
CobaltStrikeBeacon
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Sending a custom TCP request
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
obfuscated
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Malware family:
Cobalt Strike
Verdict:
Malicious
Result
Threat name:
CobaltStrike, ReflectiveLoader
Detection:
malicious
Classification:
troj.evad
Score:
84 / 100
Signature
C2 URLs / IPs found in malware configuration
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
PE file has nameless sections
Yara detected CobaltStrike
Yara detected ReflectiveLoader
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 803085 Sample: lum3ZEFtFS.exe Startdate: 09/02/2023 Architecture: WINDOWS Score: 84 36 Malicious sample detected (through community Yara rule) 2->36 38 Multi AV Scanner detection for submitted file 2->38 40 Yara detected CobaltStrike 2->40 42 4 other signatures 2->42 14 loaddll32.exe 1 2->14         started        process3 process4 16 cmd.exe 1 14->16         started        18 conhost.exe 14->18         started        process5 20 rundll32.exe 16->20         started        process6 22 rundll32.exe 20->22         started        process7 24 rundll32.exe 22->24         started        process8 26 rundll32.exe 24->26         started        process9 28 rundll32.exe 26->28         started        process10 30 rundll32.exe 28->30         started        process11 32 rundll32.exe 30->32         started        process12 34 rundll32.exe 32->34         started       
Threat name:
Win32.Trojan.CobaltStrike
Status:
Malicious
First seen:
2023-02-09 07:05:53 UTC
File Type:
PE (Dll)
AV detection:
19 of 26 (73.08%)
Threat level:
  5/5
Result
Malware family:
cobaltstrike
Score:
  10/10
Tags:
family:cobaltstrike botnet:100000
Behaviour
Suspicious use of WriteProcessMemory
Malware Config
C2 Extraction:
http://service-cetz3fn1-1308943111.sh.apigw.tencentcs.com:443/api/jquery.fancybox.min.js
Unpacked files
SH256 hash:
15f237d42968bb43de74e4a164b511efadd9864f5ee94fadbb8fd207dd59eaa5
MD5 hash:
b3da6f8cfd89a27b1e7346f1d3ccd370
SHA1 hash:
b48042611e1249a729315d8047112ec88a311c18
Detections:
cobaltstrike_xor_config
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Cobaltstrike3
Author:Ahmet Payaslioglu | Binalyze DFIR LAB
Description:Cobalt Strike Detection
Rule name:CobaltStrikeBeacon
Author:ditekshen, enzo & Elastic
Description:Cobalt Strike Beacon Payload
Rule name:CobaltStrike_C2_Encoded_XOR_Config_Indicator
Author:yara@s3c.za.net
Description:Detects CobaltStrike C2 encoded profile configuration
Rule name:CobaltStrike_ReflectiveLoader_RID3297
Author:Florian Roth
Description:Detects reflective loader (Cobalt Strike)
Reference:http://www.clearskysec.com/tulip
Rule name:CobaltStrike_Sleeve_BeaconLoader_VA_x86_o_v4_3_v4_4_v4_5_and_v4_6
Author:gssincla@google.com
Description:Cobalt Strike's sleeve/BeaconLoader.VA.x86.o (VirtualAlloc) Versions 4.3 through at least 4.6
Reference:https://cloud.google.com/blog/products/identity-security/making-cobalt-strike-harder-for-threat-actors-to-abuse
Rule name:CobaltStrike__Sleeve_BeaconLoader_VA_x86_o_v4_3_v4_4_v4_5_and_v4_6
Author:gssincla@google.com
Rule name:CS_beacon
Author:Etienne Maynier tek@randhome.io
Rule name:HKTL_CobaltStrike_Beacon_Strings
Author:Elastic
Description:Identifies strings used in Cobalt Strike Beacon DLL
Reference:https://www.elastic.co/blog/detecting-cobalt-strike-with-memory-signatures
Rule name:HKTL_Win_CobaltStrike
Author:threatintel@volexity.com
Description:The CobaltStrike malware family.
Reference:https://www.volexity.com/blog/2021/05/27/suspected-apt29-operation-launches-election-fraud-themed-phishing-campaigns/
Rule name:INDICATOR_SUSPICIOUS_ReflectiveLoader
Author:ditekSHen
Description:detects Reflective DLL injection artifacts
Rule name:meth_get_eip
Author:Willi Ballenthin
Rule name:meth_peb_parsing
Author:Willi Ballenthin
Rule name:meth_stackstrings
Author:Willi Ballenthin
Rule name:ReflectiveLoader
Author:Florian Roth (Nextron Systems)
Description:Detects a unspecified hack tool, crack or malware using a reflective loader - no hard match - further investigation recommended
Reference:Internal Research
Rule name:SUSP_XORed_Mozilla
Author:Florian Roth (Nextron Systems)
Description:Detects suspicious single byte XORed keyword 'Mozilla/5.0' - it uses yara's XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key.
Reference:https://gchq.github.io/CyberChef/#recipe=XOR_Brute_Force()
Rule name:SUSP_XORed_Mozilla_RID2DB4
Author:Florian Roth
Description:Detects suspicious XORed keyword - Mozilla/5.0
Reference:Internal Research
Rule name:WiltedTulip_ReflectiveLoader
Author:Florian Roth (Nextron Systems)
Description:Detects reflective loader (Cobalt Strike) used in Operation Wilted Tulip
Reference:http://www.clearskysec.com/tulip
Rule name:Windows_Trojan_CobaltStrike_f0b627fc
Description:Rule for beacon reflective loader
Rule name:Windows_Trojan_CobaltStrike_f0b627fc
Author:Elastic Security
Description:Rule for beacon reflective loader
Rule name:Windows_Trojan_Metasploit_7bc0f998
Description:Identifies the API address lookup function leverage by metasploit shellcode
Rule name:Windows_Trojan_Metasploit_7bc0f998
Author:Elastic Security
Description:Identifies the API address lookup function leverage by metasploit shellcode
Rule name:Windows_Trojan_Metasploit_c9773203
Description:Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families.
Reference:https://github.com/rapid7/metasploit-framework/blob/04e8752b9b74cbaad7cb0ea6129c90e3172580a2/external/source/shellcode/windows/x64/src/block/block_api.asm
Rule name:Windows_Trojan_Metasploit_c9773203
Author:Elastic Security
Description:Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families.
Reference:https://github.com/rapid7/metasploit-framework/blob/04e8752b9b74cbaad7cb0ea6129c90e3172580a2/external/source/shellcode/windows/x64/src/block/block_api.asm

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments