Backdoor

Backdoor:Win32/CobaltStrike.H!dha (file analysis)

Malware Removal

The Backdoor:Win32/CobaltStrike.H!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/CobaltStrike.H!dha virus can do?

  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Backdoor:Win32/CobaltStrike.H!dha?


File Info:

crc32: 1C2C1932
md5: 514e825867f97aaa4c1427794ac6533f
name: 514E825867F97AAA4C1427794AC6533F.mlw
sha1: 56915f4506faa030f6be3cda03dcd16167bcd9db
sha256: 1d0945da896c34ed2cbe24763a1d53dc778f4e0db3b3aeee78fea72c5070f0cf
sha512: 490c6f045944064b36835abe1170edc9e0bd98e3eb5ca66b4ea08a103813946c4daf90ad0a200ff2efb9354b31df8b2d9f08f35445829f5e7e713ba0eeb4c215
ssdeep: 384:tzyItx0mmDO8Ov/cA2e1ekd8TyJGi3nHMLKxREJKuDaJfy+bjlHQep6XB:tDxzzgAXd8TKG04jKJfpQC6R
type: PE32+ executable (GUI) x86-64, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/CobaltStrike.H!dha also known as:

LionicTrojan.Win64.Shelma.4!c
Elasticmalicious (high confidence)
ALYacGen:Variant.Cerbu.84085
CylanceUnsafe
SangforBackdoor.Win32.CobaltStrike.H
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaBackdoor:Win64/Shelma.73cb6844
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
CyrenW64/Trojan.HDQM-6878
SymantecTrojan.Gen.2
APEXMalicious
AvastWin64:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan.Win64.Shelma.icj
BitDefenderGen:Variant.Cerbu.84085
MicroWorld-eScanGen:Variant.Cerbu.84085
TencentWin64.Trojan.Shelma.Ssqw
Ad-AwareGen:Variant.Cerbu.84085
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win64.Generic.mh
FireEyeGeneric.mg.514e825867f97aaa
EmsisoftGen:Variant.Cerbu.84085 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Shelma.hiu
AviraTR/Shelma.tcmai
Antiy-AVLTrojan/Generic.ASMalwS.315BA60
MicrosoftBackdoor:Win32/CobaltStrike.H!dha
ZoneAlarmTrojan.Win64.Shelma.icj
GDataGen:Variant.Cerbu.84085
AhnLab-V3Malware/Gen.RL_Reputation.R366119
McAfeeArtemis!514E825867F9
MAXmalware (ai score=88)
VBA32Trojan.Win64.Shelma
PandaTrj/CI.A
IkarusBackdoor.Win32.CobaltStrike
MaxSecureTrojan.Malware.114274610.susgen
FortinetW64/Shelma.ICJ!tr
AVGWin64:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win64/Ransom.DogHousePower.H8oANncA

How to remove Backdoor:Win32/CobaltStrike.H!dha?

Backdoor:Win32/CobaltStrike.H!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment