Managed XDR

96520d209bd3f4908843388a5643f498.virus (Cobalt Strike) — malware analysis report

File info

Filename
96520d209bd3f4908843388a5643f498.virus
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
500.4 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
c215e56a525d820823a55da94a55673db74c40de
SHA256
f8f6ad6cafabe0d8e9a3b400e40994540b6ebc6fb5aa00aef2000ff20b6fc64e
MD5
96520d209bd3f4908843388a5643f498

Malwares

  • Cobalt Strike

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1027.002 packer_entropy: Probably contains compressed or encrypted data

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
ce_info: CobaltStrike Configuration Data found
cobaltstrike_beacon: Memory region specific for CobaltStrike beacon was found
no_graphical_activity: No graphic activity
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay

Related reports