General

  • Target

    2024-06-28_00143d69af83fb90d5cd843930017021_cobalt-strike_cobaltstrike_meterpreter

  • Size

    239KB

  • MD5

    00143d69af83fb90d5cd843930017021

  • SHA1

    37f5a6ece9f8c51a90b1e74380cabdad46f925c8

  • SHA256

    d0f7862d2ace72e78fb5cfaf666a3e0e48833e813f71b7b31661f41b8516aae7

  • SHA512

    0b0a6c68626a797ae4d70dc8707e59dee134fe7f3b662d85e9f37cb4c84cf6288f1d8b4823d7a56e84a788040492f906c785710650327110474328bc51823856

  • SSDEEP

    3072:B3vli2EJv1RBuZH3JxgYhgipvLKoTte0SqoOCtA21/wlULGs7jnZdFjdUq5rOPC:B3vyJNRkZHBvZp0qoOCu2pkojnZHjq

Score
10/10

Malware Config

Signatures

  • Cobalt Strike reflective loader 1 IoCs

    Detects the reflective loader used by Cobalt Strike.

  • Cobaltstrike family
  • Detects Reflective DLL injection artifacts 1 IoCs
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • 2024-06-28_00143d69af83fb90d5cd843930017021_cobalt-strike_cobaltstrike_meterpreter
    .exe windows:4 windows x86 arch:x86

    f34d5f2d4577ed6d9ceec516c1f5a744


    Headers

    Imports

    Sections