Risk

Win64/RiskWare.CobaltStrike.Artifact.A malicious file

Malware Removal

The Win64/RiskWare.CobaltStrike.Artifact.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/RiskWare.CobaltStrike.Artifact.A virus can do?

  • Anomalous binary characteristics

How to determine Win64/RiskWare.CobaltStrike.Artifact.A?


File Info:

crc32: CD71D133
md5: f2f313cfc30ff5593795e4518654fb03
name: F2F313CFC30FF5593795E4518654FB03.mlw
sha1: 30a0877ed734a2f1db8707b0a9f70eb5d4c8a892
sha256: 2949aec1094a9ecaaef168ef50885e49226bb9b46e8c015b74bc98772ac340e6
sha512: e482114cf9cf42126378374e02e95fc5f96f2ff4e29388aa0f6f1cae46d78025c0edd27bdb0e6fc2bdf09394bc7f40fdd81159c7875cb7f0c4746bdafb6cf247
ssdeep: 192:pDMAe4Ckj19RZZ6wpSfu1bKcq5uHj7khBDSeKNH4LI/yleBUbOj6kxiY:pDMAoKz6WtKEj7aBDix/yobAY
type: PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Win64/RiskWare.CobaltStrike.Artifact.A also known as:

Elasticmalicious (high confidence)
DrWebExploit.ShellCode.46
ClamAVWin.Trojan.CobaltStrike-9044898-1
ALYacGen:Variant.Bulz.208764
BitDefenderGen:Variant.Bulz.208764
ArcabitTrojan.Bulz.D32F7C
CyrenW64/Ulise.BW.gen!Eldorado
SymantecBackdoor.Cobalt!gen1
TrendMicro-HouseCallBackdoor.Win64.COBEACON.SMA
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
MicroWorld-eScanGen:Variant.Bulz.208764
Ad-AwareGen:Variant.Bulz.208764
SophosML/PE-A + ATK/Cobalt-A
F-SecureHeuristic.HEUR/AGEN.1139243
ZillyaTool.CobaltStrike.Win64.273
TrendMicroBackdoor.Win64.COBEACON.SMA
FireEyeGeneric.mg.f2f313cfc30ff559
EmsisoftGen:Variant.Bulz.208764 (B)
IkarusTrojan-Downloader.Win64.Agent
JiangminTrojan.Generic.fsibr
AviraHEUR/AGEN.1139243
Antiy-AVLHackTool[VirTool]/Win64.Atosev
GridinsoftTrojan.Win64.Agent.oa!s1
MicrosoftTrojan:Win32/Cobaltstrike.MK!MTB
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Bulz.208764
AhnLab-V3Malware/Win64.RL_Generic.R360995
MAXmalware (ai score=88)
MalwarebytesGeneric.Trojan.Malicious.DDS
APEXMalicious
ESET-NOD32a variant of Win64/RiskWare.CobaltStrike.Artifact.A
RisingTrojan.Shelma!8.1A3D (TFE:dGZlOgUdUGSTryxFyw)
YandexTrojan.GenAsa!ZICJWVi3Ujg
eGambitUnsafe.AI_Score_95%
FortinetW64/Agent.CY!tr
AVGWin64:Malware-gen
Cybereasonmalicious.fc30ff
AvastWin64:Malware-gen

How to remove Win64/RiskWare.CobaltStrike.Artifact.A?

Win64/RiskWare.CobaltStrike.Artifact.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment