MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9f238ad7ee69f9a519a3a82b9f90afb5cccc8db46b7b9501d7fe67df90afc9e6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CobaltStrike


Vendor detections: 15


Intelligence 15 IOCs YARA 24 File information Comments

SHA256 hash: 9f238ad7ee69f9a519a3a82b9f90afb5cccc8db46b7b9501d7fe67df90afc9e6
SHA3-384 hash: cb23b5d7759641aee3671ec7507a8d18eac7670ca0cce46c5e647efe4dd45bb25b665321dcd57cead1c614ff633140a6
SHA1 hash: 98677ae959a73c9526ce62af679b0cf9270f7ae6
MD5 hash: 39e1091865c811de41e96f38609100e6
humanhash: edward-connecticut-rugby-maine
File name:Internal Communications_230_malicious.docx
Download: download sample
Signature CobaltStrike
File size:416'463 bytes
First seen:2026-04-24 11:16:15 UTC
Last seen:Never
File type:Excel file xlsx
MIME type:application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
ssdeep 6144:X6yMzAJsd1M676mdi9Ijv2YEHU5tRHVLFwoymbdnNEE4otr8z6lj/:XAgsdPeDHU5jsSdnB4oWz4D
Threatray 2 similar samples on MalwareBazaar
TLSH T16894E01AB395BD52E923553EA9634B202FF6FCA60B28E36719D8321E5C733944CE0F51
TrID 42.4% (.XLAM) Excel Macro-enabled Open XML add-in (83500/1/13)
29.2% (.XLSM) Excel Microsoft Office Open XML Format document (with Macro) (57500/1/12)
17.3% (.XLSX) Excel Microsoft Office Open XML Format document (34000/1/7)
8.9% (.ZIP) Open Packaging Conventions container (17500/1/4)
2.0% (.ZIP) ZIP compressed archive (4000/1)
Magika xlsx
Reporter smica83
Tags:CobaltStrike xlsx

Office OLE Information


This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.

OLE dump

MalwareBazaar was able to identify 11 sections in this file using oledump:

Section IDSection sizeSection name
A10 bytesPROJECT
A20 bytesPROJECTwm
A34099 bytesVBA/DocMain
A44099 bytesVBA/Module80
A50 bytesVBA/_VBA_PROJECT
A64099 bytesVBA/dir
B10 bytesCompObj
B2400543 bytesOle10Native
B30 bytesOLE

Intelligence


File Origin
# of uploads :
1
# of downloads :
205
Origin country :
HU HU
Vendor Threat Intelligence
Malware configuration found for:
CobaltStrike MSO
Details
CobaltStrike
a configuration XOR key and verbose configuration settings
CobaltStrike
a patched binary
MSO
extracted OLE packages, if they are present within the input OOXML document
Malware family:
n/a
ID:
1
File name:
xlsx
Verdict:
No threats detected
Analysis date:
2026-04-24 11:17:10 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Detection:
CobaltStrikeBeacon
Verdict:
Malicious
Score:
91.7%
Tags:
cobaltstrike cobalt
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
DNS request
Result
Verdict:
Malicious
File Type:
OOXML Excel File with Embedding Objects and Macro
Behaviour
SuspiciousEmbeddedObjects detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 cobalt cobalt cobaltstrike exploit masquerade obfuscated packed payload windows
Verdict:
Malicious
Labled as:
Msoffice/malicious_confidence_100%
Label:
Benign
Suspicious Score:
/10
Score Malicious:
%
Score Benign:
1%
Verdict:
Malicious
File Type:
xlsm
First seen:
2026-04-17T23:49:00Z UTC
Last seen:
2026-04-18T00:05:00Z UTC
Hits:
~10
Detections:
Backdoor.Win64.Farfli.gen
Result
Threat name:
CobaltStrike
Detection:
malicious
Classification:
troj
Score:
100 / 100
Signature
C2 URLs / IPs found in malware configuration
Document contains OLE streams which likely are hidden ActiveX objects
Document contains OLE streams with names of living off the land binaries
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected CobaltStrike
Behaviour
Behavior Graph:
Gathering data
Threat name:
Win32.Trojan.Egairtigado
Status:
Malicious
First seen:
2026-04-16 20:47:14 UTC
File Type:
Document
Extracted files:
29
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Checks processor information in registry
Enumerates system info in registry
Suspicious behavior: AddClipboardFormatListener
Suspicious use of SetWindowsHookEx
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AutoIT_Script
Author:@bartblaze
Description:Identifies AutoIT script. This rule by itself does NOT necessarily mean the detected file is malicious.
Rule name:Cobaltbaltstrike_Beacon_x64
Author:Avast Threat Intel Team
Description:Detects CobaltStrike payloads
Reference:https://github.com/avast/ioc
Rule name:CobaltStrikeBeacon
Author:ditekshen, enzo & Elastic
Description:Cobalt Strike Beacon Payload
Rule name:CobaltStrike_C2_Encoded_XOR_Config_Indicator
Author:yara@s3c.za.net
Description:Detects CobaltStrike C2 encoded profile configuration
Rule name:CobaltStrike_MZ_Launcher
Author:yara@s3c.za.net
Description:Detects CobaltStrike MZ header ReflectiveLoader launcher
Rule name:CobaltStrike_Sleeve_BeaconLoader_x64_o_v4_3_v4_4_v4_5_and_v4_6
Author:gssincla@google.com
Description:Cobalt Strike's sleeve/BeaconLoader.x64.o (Base) Versions 4.3 through at least 4.6
Reference:https://cloud.google.com/blog/products/identity-security/making-cobalt-strike-harder-for-threat-actors-to-abuse
Rule name:CobaltStrike__Sleeve_BeaconLoader_x64_o_v4_3_v4_4_v4_5_and_v4_6
Author:gssincla@google.com
Rule name:Detect_all_IPv6_variants
Author:Bierchermuesli
Description:Generic IPv6 catcher
Rule name:dgaagas
Author:Harshit
Description:Uses certutil.exe to download a file named test.txt
Rule name:HKTL_CobaltStrike_Beacon_Strings
Author:Elastic
Description:Identifies strings used in Cobalt Strike Beacon DLL
Reference:https://www.elastic.co/blog/detecting-cobalt-strike-with-memory-signatures
Rule name:HKTL_Win_CobaltStrike
Author:threatintel@volexity.com
Description:The CobaltStrike malware family.
Reference:https://www.volexity.com/blog/2021/05/27/suspected-apt29-operation-launches-election-fraud-themed-phishing-campaigns/
Rule name:informational_win_ole_protected
Author:Jeff White (karttoon@gmail.com) @noottrak
Description:Identify OLE Project protection within documents.
Rule name:malware_CobaltStrike_v3v4
Author:JPCERT/CC Incident Response Group
Description:detect CobaltStrike Beacon in memory
Reference:https://blogs.jpcert.or.jp/en/2018/08/volatility-plugin-for-detecting-cobalt-strike-beacon.html
Rule name:meth_stackstrings
Author:Willi Ballenthin
Rule name:SUSP_XORed_Mozilla_Oct19
Author:Florian Roth
Description:Detects suspicious single byte XORed keyword 'Mozilla/5.0' - it uses yara's XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key.
Reference:https://gchq.github.io/CyberChef/#recipe=XOR_Brute_Force()
Rule name:SUSP_XORed_Mozilla_RID2DB4
Author:Florian Roth
Description:Detects suspicious XORed keyword - Mozilla/5.0
Reference:Internal Research
Rule name:Trojan_Raw_Generic_4
Author:FireEye
Reference:https://www.fireeye.com/blog/products-and-services/2020/12/fireeye-shares-details-of-recent-cyber-attack-actions-to-protect-community.html
Rule name:vbaproject_bin
Author:CD_R0M_
Description:{76 62 61 50 72 6f 6a 65 63 74 2e 62 69 6e} is hex for vbaproject.bin. Macros are often used by threat actors. Work in progress - Ran out of time
Rule name:Weedhack_Family_Generic
Author:jlab
Description:Generic Weedhack family detection
Rule name:Windows_Trojan_CobaltStrike_1787eef5
Author:Elastic Security
Description:CS shellcode variants
Rule name:Windows_Trojan_CobaltStrike_3dc22d14
Author:Elastic Security
Rule name:Windows_Trojan_CobaltStrike_f0b627fc
Description:Rule for beacon reflective loader
Rule name:Windows_Trojan_CobaltStrike_f0b627fc
Author:Elastic Security
Description:Rule for beacon reflective loader
Rule name:win_cobalt_strike_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.cobalt_strike.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments