MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8f280957b0f67aaa85e635f8ea7023598498a0ffbe6f8d53d7dd032ca27b632c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CobaltStrike


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 8f280957b0f67aaa85e635f8ea7023598498a0ffbe6f8d53d7dd032ca27b632c
SHA3-384 hash: 67f579fc69b5510cc8ccdd03cb56f44f623bb54d75f80c471f6e88ed37468892ae1221eca2d9684154f5e2ca15b3e0e9
SHA1 hash: f524a9ebc5e96d81c85a53c2dca92875638bdbc3
MD5 hash: 7801672edfa75401f81ea9c3d61e3089
humanhash: kansas-foxtrot-four-princess
File name:SecuriteInfo.com.Win64.Malware-gen.30039.22337
Download: download sample
Signature CobaltStrike
File size:1'077'248 bytes
First seen:2023-06-12 19:28:08 UTC
Last seen:Never
File type:Microsoft Software Installer (MSI) msi
MIME type:application/x-msi
ssdeep 24576:jtlcpVGqMpxEqB6JYcphsEt6rss7v5KV:0pQqMpOqB6lp76rL7s
Threatray 919 similar samples on MalwareBazaar
TLSH T1633559E9F2408134C66523B58CE56659BA356FE437F0808BC0C0739D6F7B5EDAB3924A
TrID 80.0% (.MSI) Microsoft Windows Installer (454500/1/170)
10.7% (.MST) Windows SDK Setup Transform script (61000/1/5)
7.8% (.MSP) Windows Installer Patch (44509/10/5)
1.4% (.) Generic OLE2 / Multistream Compound (8000/1)
Reporter SecuriteInfoCom
Tags:Cobalt Strike msi

Intelligence


File Origin
# of uploads :
1
# of downloads :
122
Origin country :
FR FR
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
alien expand.exe fingerprint lolbin packed phishing shell32.dll
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
CobaltStrike
Detection:
malicious
Classification:
troj
Score:
84 / 100
Signature
C2 URLs / IPs found in malware configuration
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected CobaltStrike
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 886224 Sample: SecuriteInfo.com.Win64.Malw... Startdate: 12/06/2023 Architecture: WINDOWS Score: 84 29 Found malware configuration 2->29 31 Malicious sample detected (through community Yara rule) 2->31 33 Multi AV Scanner detection for dropped file 2->33 35 3 other signatures 2->35 7 msiexec.exe 12 20 2->7         started        10 msiexec.exe 5 2->10         started        process3 file4 23 C:\Windows\Installer\MSIAB1F.tmp, PE32 7->23 dropped 12 msiexec.exe 5 7->12         started        process5 process6 14 expand.exe 4 12->14         started        17 ZoomInstaller.exe 12->17         started        19 cmd.exe 12->19         started        21 2 other processes 12->21 file7 25 C:\Users\user\...\ZoomInstaller.exe (copy), PE32+ 14->25 dropped 27 C:\...\39d241a9be9dd64fbda54b4ee303eda6.tmp, PE32+ 14->27 dropped
Threat name:
Win64.Backdoor.CobaltStrikeBeacon
Status:
Suspicious
First seen:
2023-06-12 19:29:06 UTC
File Type:
Binary (Archive)
Extracted files:
40
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery
Behaviour
Checks SCSI registry key(s)
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Uses Volume Shadow Copy service COM API
Drops file in Windows directory
Enumerates connected drives
Executes dropped EXE
Loads dropped DLL
Modifies file permissions
Malware family:
CobaltStrike
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CobaltStrike

Microsoft Software Installer (MSI) msi 8f280957b0f67aaa85e635f8ea7023598498a0ffbe6f8d53d7dd032ca27b632c

(this sample)

  
Delivery method
Distributed via web download

Comments