MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 21bfec8403c22b296932e59c83b18fb06b96d5210e6469d84abafc474224d77e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CobaltStrike


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 21bfec8403c22b296932e59c83b18fb06b96d5210e6469d84abafc474224d77e
SHA3-384 hash: 910b75fd7a802d3e4a16473e7300b4670445279748477de9b0e6908b9718630b12ed8a559317a28c28d59f8e65f0b9d1
SHA1 hash: b098825d87a390c8669dd759095573e66996d91f
MD5 hash: fde6e10aadcee85a64c61d4fbfc3cd29
humanhash: double-dakota-spring-mars
File name:fde6e10aadcee85a64c61d4fbfc3cd29
Download: download sample
Signature CobaltStrike
File size:204'288 bytes
First seen:2020-10-25 07:58:18 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash e66a62b251fcfbbc930b074503d08542 (24 x CobaltStrike)
ssdeep 3072:HNEfMCK7JqusgLiKG5TnN7FgkQB7R80kUzRe561:SfM5dS/JBN7jiR80Vn
Threatray 113 similar samples on MalwareBazaar
TLSH F7148CA53184D032D45B0434674BC77E5E7CBDF016A1A987BFC81E5A9E716A3EB2A303
Reporter seifreed

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Detection:
CobaltStrikeBeacon
Result
Verdict:
Malware
Maliciousness:
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
68 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 303615 Sample: 7sKF5xV1kk Startdate: 25/10/2020 Architecture: WINDOWS Score: 68 15 Malicious sample detected (through community Yara rule) 2->15 17 Antivirus / Scanner detection for submitted sample 2->17 19 Multi AV Scanner detection for submitted file 2->19 21 Machine Learning detection for sample 2->21 7 loaddll32.exe 1 2->7         started        process3 process4 9 rundll32.exe 7->9         started        11 rundll32.exe 7->11         started        process5 13 WerFault.exe 20 9 9->13         started       
Threat name:
Win32.PUA.CobaltStrikeBeacon
Status:
Malicious
First seen:
2019-07-24 21:05:53 UTC
AV detection:
30 of 31 (96.77%)
Threat level:
  1/5
Result
Malware family:
cobaltstrike
Score:
  10/10
Tags:
trojan backdoor family:cobaltstrike
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
ServiceHost packer
Cobaltstrike
Malware Config
C2 Extraction:
http://37.252.15.241:80/pixel
Unpacked files
SH256 hash:
21bfec8403c22b296932e59c83b18fb06b96d5210e6469d84abafc474224d77e
MD5 hash:
fde6e10aadcee85a64c61d4fbfc3cd29
SHA1 hash:
b098825d87a390c8669dd759095573e66996d91f
Detections:
win_cobalt_strike_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments