MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5efe564a2c779adebab8e664d524a0cfd026c8ab3a57527bd1d821245ffc2a8c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CobaltStrike


Vendor detections: 12


Intelligence 12 IOCs YARA File information Comments

SHA256 hash: 5efe564a2c779adebab8e664d524a0cfd026c8ab3a57527bd1d821245ffc2a8c
SHA3-384 hash: 7689dc590073e1941fabb1efa039cbb90e0d9b3314232d8ebfb67e9743812195d50d23dfcfc8dde79ee435ca986fe573
SHA1 hash: f575c224eebcaaf84bd7d7b1914bdd2bacb84ab9
MD5 hash: 86b248fe375c0c460955345652c2c831
humanhash: oklahoma-california-speaker-arkansas
File name:86b248fe375c0c460955345652c2c831.dll
Download: download sample
Signature CobaltStrike
File size:2'134'016 bytes
First seen:2022-08-11 06:30:45 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 72dfd4d0d41ab31566417308c282bd49 (1 x CobaltStrike)
ssdeep 49152:B1uZi3UwaehC6CJCRp0Bk0lIW9S+FCut53sI9fdWsHta8pS1SlhnrqgNSYbNP1m3:BLcS1SbbSC1m
Threatray 639 similar samples on MalwareBazaar
TLSH T188A5A193F6B251E8D8F6C1398B523627BDA1B85587399BD3960086174B32FF0E93E740
TrID 48.7% (.EXE) Win64 Executable (generic) (10523/12/4)
23.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
9.3% (.EXE) OS/2 Executable (generic) (2029/13)
9.2% (.EXE) Generic Win/DOS Executable (2002/3)
9.2% (.EXE) DOS Executable Generic (2000/1)
Reporter abuse_ch
Tags:CobaltStrike dll exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
776
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
86b248fe375c0c460955345652c2c831.dll
Verdict:
No threats detected
Analysis date:
2022-08-11 06:38:54 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Sending a custom TCP request
DNS request
Sending an HTTP GET request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
greyware
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Malware family:
Cobalt Strike
Verdict:
Malicious
Result
Threat name:
CobaltStrike
Detection:
malicious
Classification:
troj
Score:
68 / 100
Signature
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 682195 Sample: QjKK2UkV2U.dll Startdate: 11/08/2022 Architecture: WINDOWS Score: 56 26 jahojahi.com 2->26 28 Malicious sample detected (through community Yara rule) 2->28 30 Multi AV Scanner detection for submitted file 2->30 8 loaddll64.exe 1 2->8         started        signatures3 process4 process5 10 rundll32.exe 8->10         started        12 cmd.exe 1 8->12         started        14 rundll32.exe 8->14         started        16 2 other processes 8->16 process6 18 WerFault.exe 9 10->18         started        20 WerFault.exe 10->20         started        22 rundll32.exe 12->22         started        24 WerFault.exe 20 9 14->24         started       
Threat name:
Win64.Backdoor.MeterpreterReverseShell
Status:
Malicious
First seen:
2022-08-10 14:21:59 UTC
File Type:
PE+ (Dll)
AV detection:
16 of 26 (61.54%)
Threat level:
  5/5
Result
Malware family:
cobaltstrike
Score:
  10/10
Tags:
family:cobaltstrike botnet:0 backdoor trojan
Behaviour
Program crash
Cobaltstrike
Malware Config
C2 Extraction:
http://jahojahi.com:443/cr
Unpacked files
SH256 hash:
5efe564a2c779adebab8e664d524a0cfd026c8ab3a57527bd1d821245ffc2a8c
MD5 hash:
86b248fe375c0c460955345652c2c831
SHA1 hash:
f575c224eebcaaf84bd7d7b1914bdd2bacb84ab9
Malware family:
CobaltStrike
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CobaltStrike

Executable exe 5efe564a2c779adebab8e664d524a0cfd026c8ab3a57527bd1d821245ffc2a8c

(this sample)

  
Delivery method
Distributed via web download

Comments