MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8fb6ac22027c091aca002de1c40dcdd60cce76b2fb2d5be1d09a19f0028e42e7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CobaltStrike


Vendor detections: 9


Intelligence 9 IOCs YARA 9 File information Comments

SHA256 hash: 8fb6ac22027c091aca002de1c40dcdd60cce76b2fb2d5be1d09a19f0028e42e7
SHA3-384 hash: eadaf981bfcaa085b6690264a2566eda559efdb4e30106962dd60a8f34e509c97feae110f3b65a58a17fb67241995ef0
SHA1 hash: 1402a685d762541b9ba3ddc39eac82954685f832
MD5 hash: 3f2c22674b3dd1f9fc3442e57d4967aa
humanhash: ten-steak-jig-mike
File name:8fb6ac22027c091aca002de1c40dcdd60cce76b2fb2d5be1d09a19f0028e42e7
Download: download sample
Signature CobaltStrike
File size:643'808 bytes
First seen:2026-07-07 08:01:20 UTC
Last seen:2026-07-15 16:23:02 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f699a4f3268db0ba540eeac48eccfd39 (2 x CobaltStrike)
ssdeep 6144:6wrRjc4NF+KczRoLhvLTlt3iBuRNhSLCYbHK3554gGgfSiznlfvLUFU2SC5rAFEm:trRjc4T+Aso2q1qyJv5PkkP48
TLSH T1E6D4B822E222C810E56822BC22B1565C34716765D8FE9A5BEFC48DB13E9977077CFB0D
TrID 39.7% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
21.0% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
8.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
8.3% (.EXE) Win64 Executable (generic) (6522/11/2)
6.4% (.EXE) Win16 NE executable (generic) (5038/12/1)
Magika pebin
dhash icon a2a2e3e38383a2c0 (2 x CobaltStrike)
Reporter JAMESWT_WT
Tags:CobaltStrike exe Huizhou-Ningda-Times-Supply-Chain-Co-Ltd signed

Code Signing Certificate

Organisation:Huizhou Ningda Times Supply Chain Co., Ltd.
Issuer:Certum Code Signing 2021 CA
Algorithm:sha256WithRSAEncryption
Valid from:2026-04-24T01:39:15Z
Valid to:2027-04-24T01:39:14Z
Serial number: 4916ad68d1b4ec438eb47b6bee0f6183
Intelligence: 19 malware samples on MalwareBazaar are signed with this code signing certificate
Cert Graveyard Blocklist:This certificate is on the Cert Graveyard blocklist
Thumbprint Algorithm:SHA256
Thumbprint: 8256f93570e347d711f85ba5f5e5a8f10a96f173fdb0397512bcd6d9fd2dee67
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
2
# of downloads :
195
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
_8fb6ac22027c091aca002de1c40dcdd60cce76b2fb2d5be1d09a19f0028e42e7.exe
Verdict:
No threats detected
Analysis date:
2026-07-07 08:10:05 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
92.5%
Tags:
shellcode injection virus
Result
Verdict:
Clean
Maliciousness:
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cobalt cobaltstrike crypt crypto exploit microsoft_visual_cc revoked-cert signed windows
Verdict:
Malicious
Labled as:
Capa_accept_command_line_arguments
Gathering data
Threat name:
Win32.Malware.Heuristic
Status:
Malicious
First seen:
2026-06-08 10:42:53 UTC
File Type:
PE (Exe)
Extracted files:
8
AV detection:
11 of 36 (30.56%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
adware discovery persistence revoked_codesign spyware
Behaviour
Checks SCSI registry key(s)
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Enumerates connected drives
Boot or Logon Autostart Execution: Active Setup
Unpacked files
SH256 hash:
8fb6ac22027c091aca002de1c40dcdd60cce76b2fb2d5be1d09a19f0028e42e7
MD5 hash:
3f2c22674b3dd1f9fc3442e57d4967aa
SHA1 hash:
1402a685d762541b9ba3ddc39eac82954685f832
Detections:
triage_cobaltstrike_beacon_ldr
SH256 hash:
bab35b23ec75728627a7dc8270478fb4f57d51b5cecd5868d37b62f2388516bb
MD5 hash:
f7697411362b13de032b367dc089722c
SHA1 hash:
f8ab72c3ee586b26d14b8c093f566dbdaa48b36f
Detections:
triage_cobaltstrike_beacon_ldr
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:certum_issuer
Author:Certum
Description:Looks for files signed with certificate issued by Certum
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:detect_certum_issuer
Author:Certum
Description:Looks for files signed with certificate issued by Certum
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:meth_peb_parsing
Author:Willi Ballenthin
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:Windows_Trojan_CobaltStrike_f0b627fc
Description:Rule for beacon reflective loader
Rule name:Windows_Trojan_CobaltStrike_f0b627fc
Author:Elastic Security
Description:Rule for beacon reflective loader

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments