Trojan

What is “Trojan.Win32.Cobalt.ekb”?

Malware Removal

The Trojan.Win32.Cobalt.ekb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Cobalt.ekb virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.Win32.Cobalt.ekb?


File Info:

name: 04608335729F10A1372E.mlw
path: /opt/CAPEv2/storage/binaries/2779cca0456cf0247f3ad22414b8a97bd5d54657a4ed13b89ee65beaa5edb0e7
crc32: 7B0C959B
md5: 04608335729f10a1372eee082a482918
sha1: e85ffafdb3f4a6dcc8d6caccfd5d715d0b1bbb10
sha256: 2779cca0456cf0247f3ad22414b8a97bd5d54657a4ed13b89ee65beaa5edb0e7
sha512: e03e4b07c0edd7204da9475574dd8eb2366e045646ecef221486a7dbf6fec024793e20c15b772e17628d7096d78066301e3d4f2d98ba07a2bc111bb429bdb6df
ssdeep: 49152:S8G/tgJgp77K8s7ogQlnKRk4zvjPhZARO/buXzYmPsR1+XmxPyG5F1F:VYtw8hlnak4ztZH/CXsJ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F6066B40F9DB84F6E603453044ABA3BFAB30AA098739CBD3D6486F5BE877AD14D72115
sha3_384: 5d7603d2166a8cd65624b05539b0c6dab42b7dac4ece936be752e0f79bcf45a73fd6b00350ab876924986283bf678a41
ep_bytes: e92bdbffffcccccccccccccccccccccc
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Cobalt.ekb also known as:

MicroWorld-eScanTrojan.GenericKD.46636592
FireEyeTrojan.GenericKD.46636592
McAfeeArtemis!04608335729F
CylanceUnsafe
ZillyaTrojan.Encoder.Win32.2520
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Cobalt.922d8c17
CyrenW32/Trojan.QNHR-0587
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0WGJ21
KasperskyTrojan.Win32.Cobalt.ekb
BitDefenderTrojan.GenericKD.46636592
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.46636592
EmsisoftTrojan.GenericKD.46636592 (B)
TrendMicroTROJ_GEN.R002C0WGJ21
McAfee-GW-EditionBehavesLike.Win32.BadFile.wh
SophosGeneric PUA OI (PUA)
APEXMalicious
GDataTrojan.GenericKD.46636592
JiangminTrojan.Cobalt.ou
AviraTR/Cobalt.orctw
MAXmalware (ai score=88)
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4557646
VBA32TrojanRansom.Encoder
ALYacTrojan.GenericKD.46636592
RisingTrojan.Generic@ML.84 (RDMK:z6SXS2ddX4SCxRHjxfclFQ)
YandexTrojan.Cobalt!J8yMRcLkywE
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.119761428.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Trojan.Win32.Cobalt.ekb?

Trojan.Win32.Cobalt.ekb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment