Trojan

Trojan:Win32/CobaltStrike.SS!MTB removal

Malware Removal

The Trojan:Win32/CobaltStrike.SS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/CobaltStrike.SS!MTB virus can do?

  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous binary characteristics

How to determine Trojan:Win32/CobaltStrike.SS!MTB?


File Info:

crc32: D6B78D43
md5: c28490191342f8f261aade77998ad515
name: C28490191342F8F261AADE77998AD515.mlw
sha1: b483d5a5d6d77d599acbec2a6103f6ead6627f1c
sha256: af2c6a5fd08b59d5671ab00c39470b175b5fa10fdbfc82de39ea7e72e8baa8fe
sha512: 32dada24079664bbe5f53bcd8e2b473e9d4cd20b24aa2326e18757a6dfd3c306ac513011f2eee566b71bfd33cb94d294aafff6097f3e285f050a6db7c46563fe
ssdeep: 384:rCxRK3AaSUjuSfBPk+xz3wCwl4ffCXAn:rCxKoUSSfJk4KmffiA
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/CobaltStrike.SS!MTB also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004f12031 )
Elasticmalicious (high confidence)
DrWebTrojan.Swrort.41
CynetMalicious (score: 100)
CAT-QuickHealTrojanAPT.Cobalt.A7
ALYacGen:Variant.Ursu.22380
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 004f12031 )
Cybereasonmalicious.91342f
CyrenW32/Diple.G.gen!Eldorado
ESET-NOD32a variant of Win32/Rozena.AMZ
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Countermeasure.LoaderWinGeneric-9804845-2
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.22380
NANO-AntivirusTrojan.Win32.Swrort.fahmzc
MicroWorld-eScanGen:Variant.Ursu.22380
Ad-AwareGen:Variant.Ursu.22380
SophosML/PE-A + ATK/Cobalt-B
F-SecureHeuristic.HEUR/AGEN.1139243
BitDefenderThetaAI:Packer.69783ECC1E
TrendMicroTrojan.Win32.COBALT.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.lm
FireEyeGeneric.mg.c28490191342f8f2
EmsisoftGen:Variant.Ursu.22380 (B)
AviraHEUR/AGEN.1139243
eGambitUnsafe.AI_Score_52%
MicrosoftTrojan:Win32/CobaltStrike.SS!MTB
ArcabitTrojan.Ursu.D576C
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ursu.22380
AhnLab-V3Trojan/Win32.CobaltStrike.R329694
McAfeeTrojan-Cobalt!C28490191342
MAXmalware (ai score=80)
MalwarebytesTrojan.Rozena
TrendMicro-HouseCallTrojan.Win32.COBALT.SM
RisingMalware.Heuristic!ET#91% (RDMK:cmRtazqaRV2Xs/iRUMEsZBnDoGKA)
YandexTrojan.GenAsa!/C5jzoNrl5s
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Generic.AP.118EACE!tr
AVGWin32:Malware-gen
Qihoo-360HEUR/QVM20.1.DAFA.Malware.Gen

How to remove Trojan:Win32/CobaltStrike.SS!MTB?

Trojan:Win32/CobaltStrike.SS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment