MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 30e835866395298b102bb0bc62ea0d2f8aa26bd06bb38a6dc4112beb4df2219f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CobaltStrike


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: 30e835866395298b102bb0bc62ea0d2f8aa26bd06bb38a6dc4112beb4df2219f
SHA3-384 hash: 7c92e4c85fb11da86652c897abfb86dec7e3ca7330237b53194fb6e0804e33d1009a983597b6398b19d2c15d067895ad
SHA1 hash: d623c9bb721f0a30770acd6f67053f6554185ba9
MD5 hash: 7df806ff482d88dc652a634338ef616b
humanhash: enemy-nitrogen-paris-berlin
File name:30e835866395298b102bb0bc62ea0d2f8aa26bd06bb38a6dc4112beb4df2219f
Download: download sample
Signature CobaltStrike
File size:430'592 bytes
First seen:2023-08-11 15:00:55 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 0104663fe1ade3974a7b185f8d21896d (1 x CobaltStrike)
ssdeep 6144:z40y4KNS/BG2J0d/16U/YQ9Ikg75nV3h/HX3C0sWpGTv/+UAXKKz/:z+0/X0dt6Ugtp75//nC0JcTv/+UAp/
Threatray 5 similar samples on MalwareBazaar
TLSH T1C894F3C6B71BECF9CBF3C076A11163353E89EAC140919E374761C7B96D35908A85ACB1
TrID 44.4% (.EXE) Win64 Executable (generic) (10523/12/4)
21.2% (.EXE) Win16 NE executable (generic) (5038/12/1)
8.6% (.ICL) Windows Icons Library (generic) (2059/9)
8.5% (.EXE) OS/2 Executable (generic) (2029/13)
8.4% (.EXE) Generic Win/DOS Executable (2002/3)
Reporter Anonymous
Tags:Cobalt Strike exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
312
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
30e835866395298b102bb0bc62ea0d2f8aa26bd06bb38a6dc4112beb4df2219f
Verdict:
No threats detected
Analysis date:
2023-08-11 15:02:37 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
DNS request
Launching the default Windows debugger (dwwin.exe)
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
anti-debug
Result
Threat name:
CobaltStrike
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
System process connects to network (likely due to code injection or exploit)
Yara detected CobaltStrike
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1290114 Sample: C6bE7V94CA.exe Startdate: 11/08/2023 Architecture: WINDOWS Score: 100 28 Multi AV Scanner detection for domain / URL 2->28 30 Found malware configuration 2->30 32 Malicious sample detected (through community Yara rule) 2->32 34 4 other signatures 2->34 7 loaddll64.exe 7 2->7         started        process3 dnsIp4 24 nesanocige.us 7->24 10 regsvr32.exe 6 7->10         started        14 cmd.exe 1 7->14         started        16 WerFault.exe 17 9 7->16         started        18 4 other processes 7->18 process5 dnsIp6 26 nesanocige.us 104.238.57.119, 443, 49711, 49712 ASN-QUADRANET-GLOBALUS United States 10->26 36 System process connects to network (likely due to code injection or exploit) 10->36 20 WerFault.exe 20 9 10->20         started        22 rundll32.exe 14->22         started        signatures7 process8
Threat name:
Win64.Backdoor.CobaltStrikeBeacon
Status:
Malicious
First seen:
2023-08-03 01:01:49 UTC
File Type:
PE+ (Dll)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
cobaltstrike
Score:
  10/10
Tags:
family:cobaltstrike backdoor trojan
Behaviour
Program crash
Cobaltstrike
Malware Config
C2 Extraction:
http://nesanocige.us:443/files/favicon.ico
Unpacked files
SH256 hash:
30e835866395298b102bb0bc62ea0d2f8aa26bd06bb38a6dc4112beb4df2219f
MD5 hash:
7df806ff482d88dc652a634338ef616b
SHA1 hash:
d623c9bb721f0a30770acd6f67053f6554185ba9
Malware family:
CobaltStrike
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments