Trojan

How to remove “Trojan.Win32.Cobalt.hkr”?

Malware Removal

The Trojan.Win32.Cobalt.hkr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Cobalt.hkr virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Win32.Cobalt.hkr?


File Info:

name: 0E4E4474A231A23E609D.mlw
path: /opt/CAPEv2/storage/binaries/99fa804be2393a3507dc254556a7a561305a859e068a6328767d94a31811dc60
crc32: 8783E308
md5: 0e4e4474a231a23e609d1fd13d0cee58
sha1: 02585c68c5823c161744536cd78ebc4078d25248
sha256: 99fa804be2393a3507dc254556a7a561305a859e068a6328767d94a31811dc60
sha512: f2567daee920afd027497e70f997f72a706ce0d09e0ffaaffbf22dcb3933afcd36256cb6fa4ea131e16d1b6ffc3ef4936fe85a813a67525f52cf268451d23f56
ssdeep: 12288:mqtdvPYcz1/XO8ooCIPwEBQyAEpdagpS01rTMftqbWbwMfAcOmoqUo3Qa6McIcU:dFPYczA85CI1BrQgpS0pWUzmoq3Qa4fU
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T18C05BFB8B21428F5E93F423FCD966D89937239234B97D5CF426467C31E633A1EE26901
sha3_384: e970984d2e74489a8f566239d83b1e995b0132f3028e9af922004fb1e6c4f1e58956043f5ad2ce1ec5f7d99e1c0b3269
ep_bytes: 4883ec28e85b0600004883c428e972fe
timestamp: 2021-11-22 15:03:55

Version Info:

0: [No Data]

Trojan.Win32.Cobalt.hkr also known as:

LionicTrojan.Win32.Cobalt.4!c
MicroWorld-eScanTrojan.GenericKD.47568644
CAT-QuickHealTrojan.Cobalt
McAfeeArtemis!0E4E4474A231
AlibabaTrojan:Win32/Cobalt.9d7d4a04
Cybereasonmalicious.8c5823
SymantecTrojan.Gen.MBT
APEXMalicious
KasperskyTrojan.Win32.Cobalt.hkr
BitDefenderTrojan.GenericKD.47568644
AvastWin64:Malware-gen
Ad-AwareTrojan.GenericKD.47568644
EmsisoftTrojan.GenericKD.47568644 (B)
TrendMicroTROJ_GEN.R067C0WL821
McAfee-GW-EditionBehavesLike.Win64.Generic.cm
FireEyeTrojan.GenericKD.47568644
SophosMal/Generic-R
IkarusMalware.Win32.CobalStrike
GDataWin32.Malware.CobalStrike.IUIG4N
AviraHEUR/AGEN.1144435
ArcabitTrojan.Generic.D2D5D704
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.47568644
MAXmalware (ai score=88)
TrendMicro-HouseCallTROJ_GEN.R067C0WL821
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/PossibleThreat
AVGWin64:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan.Win32.Cobalt.hkr?

Trojan.Win32.Cobalt.hkr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment