Trojan

MemScan:Trojan.CobaltStrike.FM (file analysis)

Malware Removal

The MemScan:Trojan.CobaltStrike.FM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Trojan.CobaltStrike.FM virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Tamil
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Attempts to modify proxy settings

How to determine MemScan:Trojan.CobaltStrike.FM?


File Info:

name: 3C5419E33563E247FCD5.mlw
path: /opt/CAPEv2/storage/binaries/c761ebbde80dfeb9047355a7e9f80ed835c4245bdb9b304620c10127eef8679f
crc32: 0FA096CF
md5: 3c5419e33563e247fcd561992fb30e27
sha1: fcf628b172d579f7f6a66d2421d2a489e43d1959
sha256: c761ebbde80dfeb9047355a7e9f80ed835c4245bdb9b304620c10127eef8679f
sha512: e6924599e1df0ab97bf307be9a88c707ff739523f8e3998e929d45db60e3c433d571baf954e25be3087e6ff42221d4579b6be806124790a381348b1155025f31
ssdeep: 1536:FsCn2EbEbEeCf/k2VulmP6tgbKK/m1TGANiDfFnE4TbaMymCBe5nSBf/j2Q:F5nhbEbJCf/k2Vul7tgbKom1TGBDtnEX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D693019E01BA0D14EE236D32668AFFD1D7047C5C488B2BE70F78726C79BA8D115B8166
sha3_384: c36f34e721a89ac5dbbfed9dca9a4b183214b0723a8ab72d3bb0df56aa45a57131998f781cc50842f1a73e6e635db506
ep_bytes: 60be00e042008dbe0030fdff57eb0b90
timestamp: 2018-04-29 15:12:18

Version Info:

InternalName: ropadesu.exe
Translation: 0x0449 0x04b1

MemScan:Trojan.CobaltStrike.FM also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.CobaltStrike.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanMemScan:Trojan.CobaltStrike.FM
FireEyeGeneric.mg.3c5419e33563e247
ALYacMemScan:Trojan.CobaltStrike.FM
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005465141 )
AlibabaRansom:Win32/GandCrab.d2d1fd9e
K7GWTrojan ( 005465141 )
Cybereasonmalicious.33563e
CyrenW32/GandCrab.AF.gen!Eldorado
SymantecPacked.Generic.534
ESET-NOD32a variant of Win32/Kryptik.GOZL
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Gandcrab-6846115-0
KasperskyTrojan.Win32.CobaltStrike.gm
BitDefenderMemScan:Trojan.CobaltStrike.FM
NANO-AntivirusTrojan.Win32.Kryptik.fmkpai
AvastWin32:Trojan-gen
TencentWin32.Trojan.Inject.Auto
Ad-AwareMemScan:Trojan.CobaltStrike.FM
SophosMal/Generic-S
DrWebTrojan.Swrort.41
TrendMicroRansom_GandCrab.R002C0CKQ21
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.mc
EmsisoftMemScan:Trojan.CobaltStrike.FM (B)
IkarusTrojan-Downloader.Win32.SmokeLoader
GDataMemScan:Trojan.CobaltStrike.FM
JiangminTrojanDownloader.Bandit.ck
WebrootW32.Rimecud.Gen
AviraHEUR/AGEN.1120552
Antiy-AVLTrojan/Generic.ASMalwS.2A77FD2
MicrosoftRansom:Win32/GandCrab.BB!bit
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Malpacked.Exp
McAfeeArtemis!3C5419E33563
MAXmalware (ai score=82)
VBA32BScope.Trojan.Chapak
TrendMicro-HouseCallRansom_GandCrab.R002C0CKQ21
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
YandexTrojan.GenAsa!cdmLzVxKhck
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/Kryptik.CNB!tr
BitDefenderThetaGen:NN.ZexaF.34294.fmKfaCPb!zli
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.74098281.susgen

How to remove MemScan:Trojan.CobaltStrike.FM?

MemScan:Trojan.CobaltStrike.FM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment