Trojan

Trojan:Win32/CobaltStrike.C!MTB removal guide

Malware Removal

The Trojan:Win32/CobaltStrike.C!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/CobaltStrike.C!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/CobaltStrike.C!MTB?


File Info:

name: 72AD1225ACC863AFB8F5.mlw
path: /opt/CAPEv2/storage/binaries/9a56b90a435a703f2a76a6b1114519a422446161c43c28aa9f2f589477a91a09
crc32: 098EC1F1
md5: 72ad1225acc863afb8f59b2f2008f1c8
sha1: 6e9b6ae5a3b06c5ae1aff8d1a031a6d58aad9a21
sha256: 9a56b90a435a703f2a76a6b1114519a422446161c43c28aa9f2f589477a91a09
sha512: a5ec0a6bfa07c5a71aa754987510f5f62d5d1e91c562c3bd51e69d7040f992ac13ade485b65e7d510ccee1d68e122c95cb131fc63d81acbb0b611dc940415918
ssdeep: 24576:eK/fWX8kflYmo/39tFhoNgjX1H1MhNp0ffFuYGGsj21PQW0S2pCyRPwsMj:xfd4lY9/NYgxeNyCxRPwHj
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1DA05F16283587A46C0C8B5FB850C9B2404B16872A65FFCC66BB11A3736DF58D877CEC6
sha3_384: 8f6d24a148a793f85d5af47de9aa86af073af0bf5b3fd121c1807550e5d4a77e9a6f01d1e2f3168abb02856fc35c97b0
ep_bytes: 558bec837d0c017505e884010000ff75
timestamp: 2023-08-09 07:25:51

Version Info:

0: [No Data]

Trojan:Win32/CobaltStrike.C!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.DInvoke.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.417083
FireEyeGen:Variant.Lazy.417083
SkyhighRDN/generic.dx
McAfeeRDN/generic.dx
Cylanceunsafe
ZillyaTrojan.Inject.Win32.343193
SangforTrojan.Win32.Inject.V3l3
K7AntiVirusTrojan ( 0055dd121 )
K7GWTrojan ( 0055dd121 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Nvcertleak!g1
ESET-NOD32a variant of Win32/Inject.NJV
KasperskyTrojan.MSIL.DInvoke.aqm
BitDefenderGen:Variant.Lazy.417083
NANO-AntivirusTrojan.Win32.DInvoke.kcnjeh
AvastWin32:Dh-A [Heur]
TencentMalware.Win32.Gencirc.11b7afab
EmsisoftGen:Variant.Lazy.417083 (B)
F-SecureTrojan.TR/AD.Nekark.rjptg
DrWebTrojan.Inject4.62842
VIPREGen:Variant.Lazy.417083
TrendMicroTROJ_GEN.R002C0DBC24
Trapminesuspicious.low.ml.score
IkarusTrojan.Win32.Generic
GDataGen:Variant.Lazy.417083
JiangminTrojan.MSIL.aoqdu
GoogleDetected
AviraTR/AD.Nekark.rjptg
VaristW32/ABRisk.DSGD-4587
Antiy-AVLTrojan/Win32.Inject
ArcabitTrojan.Lazy.D65D3B
ZoneAlarmTrojan.MSIL.DInvoke.aqm
MicrosoftTrojan:Win32/CobaltStrike.C!MTB
CynetMalicious (score: 100)
ALYacGen:Variant.Lazy.417083
MAXmalware (ai score=80)
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0DBC24
RisingTrojan.Inject!8.103 (TFE:5:PrScJPTQv1O)
FortinetW32/Inject.NJV!tr
AVGWin32:Dh-A [Heur]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/CobaltStrike.C!MTB?

Trojan:Win32/CobaltStrike.C!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment