Trojan

Should I remove “Trojan:Win32/Cobaltstrike”?

Malware Removal

The Trojan:Win32/Cobaltstrike is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Cobaltstrike virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Cobaltstrike?


File Info:

crc32: B298CEF5
md5: 379435cc19c931e2b19d7470649ffc35
name: upload_file
sha1: 973383e9513347d0cbf223b15532001988e5b034
sha256: 5daf37825cdc2b41a078b9a4b73c62700c2a6e41ae7d696b3fa644310109c253
sha512: 55f2decb80e2a2ed13cb46d8336231d4d7d2cbe45d5ecc488cbfd6a9937b6625300cbbb8ac65dcfaca6d0f15d888d85bfab711725e5b59d9e0067a227e83ffc6
ssdeep: 12288:SVVd8Umx+REJsBElsJYmVg0mqtPNUmu+vAQwIDNcxEJ:SVVd8UuRlsJH2QPSmu+IQdDNcxQ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: (C) 2020 philandro Software GmbH
FileVersion: 6.0.5.0
CompanyName: philandro Software GmbH
ProductName: AnyDesk
ProductVersion: 6.0
FileDescription: AnyDesk
Translation: 0x0409 0x04e4

Trojan:Win32/Cobaltstrike also known as:

MicroWorld-eScanTrojan.GenericKD.34803852
CAT-QuickHealTrojan.Win64
Qihoo-360Win64/Trojan.172
McAfeeRDN/Generic.dx
CylanceUnsafe
ZillyaTrojan.Inject.Win32.307462
AegisLabTrojan.Win64.CozyDuke.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.34803852
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_60% (W)
ArcabitTrojan.Generic.D213108C
TrendMicroTROJ_GEN.R03BC0PJH20
BitDefenderThetaGen:NN.ZelphiF.34590.SmKfaWIOqooG
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.FRBISCH
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win64.CozyDuke.vl
AlibabaTrojan:Win64/CozyDuke.911aec25
NANO-AntivirusTrojan.Win32.Inject.hzxkyf
ViRobotTrojan.Win32.Z.Wacatac.732160.B
Ad-AwareTrojan.GenericKD.34803852
EmsisoftTrojan.GenericKD.34803852 (B)
ComodoMalware@#f2hta1sfmsxt
F-SecureTrojan.TR/AD.CobaltStrike.fiviy
DrWebBackDoor.Meterpreter.163
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.bc
FireEyeGeneric.mg.379435cc19c931e2
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
JiangminTrojan.Inject.bmhn
WebrootW32.Adware.Gen
AviraTR/AD.CobaltStrike.fiviy
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Generic
MicrosoftTrojan:Win32/Cobaltstrike
ZoneAlarmTrojan.Win64.CozyDuke.vl
GDataTrojan.GenericKD.34803852
CynetMalicious (score: 90)
AhnLab-V3Trojan/Win32.Obfuscated.C4207333
VBA32Trojan.Inject
ALYacTrojan.GenericKD.34803852
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R03BC0PJH20
TencentWin64.Trojan.Cozyduke.Lkxo
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/Malicious_Behavior.VEX
AVGWin32:Malware-gen
Cybereasonmalicious.951334
Paloaltogeneric.ml
MaxSecureTrojan.Malware.11926561.susgen

How to remove Trojan:Win32/Cobaltstrike?

Trojan:Win32/Cobaltstrike removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment