MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d0c88b0ca2a78ef90470498fa686ad63e3473a4fc1337b2850461ecc07bd5b34. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CobaltStrike


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: d0c88b0ca2a78ef90470498fa686ad63e3473a4fc1337b2850461ecc07bd5b34
SHA3-384 hash: 7855f3a538cf77184fba4941f8b889027a528160224dc2f44e3ca2b18dafb1b9002b5bca0ce53b6ff955d5504b8fd62c
SHA1 hash: 2d6d3236c0db3a94fa3ee24b13235bdadca60d1b
MD5 hash: 2f4cd697a40de0d752287e03f3175a17
humanhash: victor-helium-kentucky-bakerloo
File name:2f4cd697a40de0d752287e03f3175a17.exe
Download: download sample
Signature CobaltStrike
File size:72'196 bytes
First seen:2020-11-05 06:26:46 UTC
Last seen:2020-11-05 08:10:25 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash c7d4cffcfde489cf0e0b819bfeb844f3 (1 x CobaltStrike)
ssdeep 768:0twMI0V0eritDFnMjjk7yZ8oFYwVy2n4U3A2rDxIVyi2zNKZ9c8WWAsWjcdO+2D3:0I0edMjjkdwY24F2PnKc8qsWjcdOHKBu
Threatray 125 similar samples on MalwareBazaar
TLSH 3B636B0376D188B1E4B70BB509F4CA515B6FBD225E748D6B3788118E4A312E09F36FA3
Reporter abuse_ch
Tags:CobaltStrike exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
90
Origin country :
n/a
Vendor Threat Intelligence
Detection:
CobaltStrikeBeacon
Result
Verdict:
Clean
Maliciousness:

Behaviour
DNS request
Sending a custom TCP request
Sending an HTTP GET request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
60 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Cometsys
Status:
Malicious
First seen:
2020-10-21 20:15:15 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Result
Malware family:
cobaltstrike
Score:
  10/10
Tags:
family:cobaltstrike backdoor trojan
Behaviour
Modifies system certificate store
Cobaltstrike
Malware Config
C2 Extraction:
http://beltpost.com:443/us/ky/louisville/312-s-fourth-st.html
http://sslcar.com:443/us/ky/louisville/312-s-fourth-st.html
http://livenx.com:443/us/ky/louisville/312-s-fourth-st.html
http://stylesam.com:443/us/ky/louisville/312-s-fourth-st.html
http://epicnut.com:443/us/ky/louisville/312-s-fourth-st.html
Unpacked files
SH256 hash:
d0c88b0ca2a78ef90470498fa686ad63e3473a4fc1337b2850461ecc07bd5b34
MD5 hash:
2f4cd697a40de0d752287e03f3175a17
SHA1 hash:
2d6d3236c0db3a94fa3ee24b13235bdadca60d1b
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments