MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2b29c80a4829d3dc816b99606aa5aeead3533d24137f79b5c9a8407957e97b10. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CobaltStrike


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 2b29c80a4829d3dc816b99606aa5aeead3533d24137f79b5c9a8407957e97b10
SHA3-384 hash: 17fcebab6b1dd2ab2189cfcfd593b9a57c945cea7ffc60f61d258c54bf24127d3b0a2cb15aac471b70d07a1693374322
SHA1 hash: cfd11187f820e2f915bce06a32ad4dc71ac340c2
MD5 hash: af41813cc051b8d0c9c418e99ba345c6
humanhash: pennsylvania-neptune-echo-mississippi
File name:trendmicro2.dll
Download: download sample
Signature CobaltStrike
File size:1'202'688 bytes
First seen:2021-10-29 20:27:40 UTC
Last seen:2021-10-30 04:19:15 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash ccd94d54b49b113bd9c8eb4e3fa720ca (1 x CobaltStrike)
ssdeep 24576:h+5jq+9BGqWeU33V8V0HmkKaH1S2807SPFL3EOGTWqG5QVEzAJ24GOy2irA8+fj7:h+keU33V8V0HmkKaH1S277SPFL3EOGTZ
Threatray 18 similar samples on MalwareBazaar
TLSH T12E45D683EA7361E0E4BBD23582A67627B97135148334C78B87015B175B62FF4D9BE388
Reporter KodaES
Tags:CobaltStrike exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
535
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
trendmicro2.dll
Verdict:
No threats detected
Analysis date:
2021-10-28 14:00:52 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Multi AV Scanner detection for submitted file
Sigma detected: CobaltStrike Named Pipe
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 512035 Sample: trendmicro2.dll Startdate: 29/10/2021 Architecture: WINDOWS Score: 56 28 Multi AV Scanner detection for submitted file 2->28 30 Sigma detected: CobaltStrike Named Pipe 2->30 7 loaddll64.exe 1 2->7         started        process3 process4 9 iexplore.exe 1 73 7->9         started        11 cmd.exe 1 7->11         started        13 regsvr32.exe 7->13         started        15 3 other processes 7->15 process5 17 iexplore.exe 2 144 9->17         started        20 rundll32.exe 11->20         started        dnsIp6 22 dart.l.doubleclick.net 216.58.215.230, 443, 49821, 49822 GOOGLEUS United States 17->22 24 geolocation.onetrust.com 104.20.185.68, 443, 49795, 49796 CLOUDFLARENETUS United States 17->24 26 11 other IPs or domains 17->26
Threat name:
Win64.Trojan.Bazarloader
Status:
Malicious
First seen:
2021-10-28 18:38:38 UTC
AV detection:
17 of 45 (37.78%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
2b29c80a4829d3dc816b99606aa5aeead3533d24137f79b5c9a8407957e97b10
MD5 hash:
af41813cc051b8d0c9c418e99ba345c6
SHA1 hash:
cfd11187f820e2f915bce06a32ad4dc71ac340c2
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CobaltStrike

Executable exe 2b29c80a4829d3dc816b99606aa5aeead3533d24137f79b5c9a8407957e97b10

(this sample)

  
Delivery method
Distributed via web download

Comments