Static | ZeroBOX

PE Compile Time

2020-06-09 09:17:28

PE Imphash

17b461a082950fc6332228572138b80c

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000020f0 0x00002200 6.03397581892
.data 0x00004000 0x00042490 0x00042600 7.09140703278
.rdata 0x00047000 0x000002d0 0x00000400 4.00037373567
.pdata 0x00048000 0x0000027c 0x00000400 2.97342307908
.xdata 0x00049000 0x00000238 0x00000400 2.65379684452
.bss 0x0004a000 0x00000a30 0x00000000 0.0
.idata 0x0004b000 0x00000958 0x00000a00 4.1419693576
.CRT 0x0004c000 0x00000068 0x00000200 0.256446748701
.tls 0x0004d000 0x00000048 0x00000200 0.217769955458

Imports

Library KERNEL32.dll:
0x44b244 CloseHandle
0x44b24c ConnectNamedPipe
0x44b254 CreateFileA
0x44b25c CreateNamedPipeA
0x44b264 CreateThread
0x44b27c GetCurrentProcess
0x44b284 GetCurrentProcessId
0x44b28c GetCurrentThreadId
0x44b294 GetLastError
0x44b29c GetModuleHandleA
0x44b2a4 GetProcAddress
0x44b2ac GetStartupInfoA
0x44b2bc GetTickCount
0x44b2d4 LoadLibraryW
0x44b2e4 ReadFile
0x44b2ec RtlAddFunctionTable
0x44b2f4 RtlCaptureContext
0x44b304 RtlVirtualUnwind
0x44b314 Sleep
0x44b31c TerminateProcess
0x44b324 TlsGetValue
0x44b334 VirtualAlloc
0x44b33c VirtualProtect
0x44b344 VirtualQuery
0x44b34c WriteFile
Library msvcrt.dll:
0x44b364 __dllonexit
0x44b36c __getmainargs
0x44b374 __initenv
0x44b37c __iob_func
0x44b384 __lconv_init
0x44b38c __set_app_type
0x44b394 __setusermatherr
0x44b39c _acmdln
0x44b3a4 _amsg_exit
0x44b3ac _cexit
0x44b3b4 _fmode
0x44b3bc _initterm
0x44b3c4 _lock
0x44b3cc _onexit
0x44b3d4 _unlock
0x44b3dc abort
0x44b3e4 calloc
0x44b3ec exit
0x44b3f4 fprintf
0x44b3fc free
0x44b404 fwrite
0x44b40c malloc
0x44b414 memcpy
0x44b41c signal
0x44b424 sprintf
0x44b42c strlen
0x44b434 strncmp
0x44b43c vfprintf

!This program cannot be run in DOS mode.
P`.data
.rdata
P@.pdata
0@.xdata
0@.bss
.idata
ffffff.
ATUWVSH
[^_]A\
ATUWVSH
@[^_]A\
ATUWVSH
[^_]A\
ATUWVSH
@[^_]A\
ffffff.
AUATUWVSH
[^_]A\A]
[^_]A\A]
[^_]A\A]
ATWVSH
[^_A\]
ATUWVSH
@[^_]A\
L3d$0H
@[^_]A\
([^_]H
/,p!.,
/,<i,,
/,NH-,
bEJS/,
jh(9#Q;
h&e7:n
P#;0/,
gE|S/,
e?"'d5
d7,gE|S/,
=m?#+m7
/d?'wm
/,9#ZS
a.,7$g
k.,7 g
/,U=/,
/,9#Z37w
/d='_.
+,9#Z$1
m7(j/D
]}+$i7,
m})9m7"
}+$h1`
7 k/Mh
}*6th
}+-m70kt
}*6i1a
#y}+$m79
:}+)t
}+)th
!7,kL
}*6th
7-n'r"
}+"m7-kt
:}+)t
}(9m7*
}+)th
}+"m7)kd
m7,j/d
g[f}+$m7
!7-n'r
m7 k/E
}+$i72
}+"m7*
}+$h1e~Ov
m7(k/~"
8}*6t
}*6i1d
7,j/t"
5}+$t
m7",at
m7-n/d
%I}+$h78
m7$k/e"
}+"m7(
m7*n/D
:}+)th
}*6m74j
}+)th
7 k/Mh
}*6th
m7(j/D
}+"m7,kl
7%k/mh
?@~@{"
:}+)t
}-9m7(
!7,kL
}*6th
7-n'r"
}+)th
}+"m7)kd
m7$k/e"
}*6i7$
}+)thj0})9)O
}+)th
m77ni
m7,n/d
}+$h78
m})9m7%k
m7 k/}
:}+)t
$n/djs
$n 9MH
kk#Ji.d1
mFkk#I
nW!U-/,
/,U /,
h7 g/r
/,U9/,
gj.e7-
?d9*[0
h d9*Z
/#83.,
/,U_.,
/,Uw.,
`7$f/ujr
nw<9#[2
Wd?'om
h7"g/k
P#8v/,
+,9#[(
n^S8#V
C"I/ng
mC#Im5
##2c/,
\%? +`7
/,Uo/,
<YRin-
/,U:/,
7<Us/,
,#;O/,
#("n/}
/,Uo/,
9YRin-
nd.8#V
.#;q/,
/#;S/,
h$e? +
e?"+/yj(
/,9#Z0
?dC%&-C
/,9#Zz7
jm$T@<,
h!mC$b
m75ju
Sh)/k"
/d7"Z/
/d72Z/
/,9#Zx
Od?'om
/d7:[
/,9#Z]7
/,9#Z37
h.`7)g
0d?"+eC+Z
/,9#Z@
/d? +d
~j>d?'
gm7#g/lh
hi<7(n
mC)fOv
i9#[${
`7"gOtf
/,UU/,
d?$7dC-Z
d?$7dC(Z
m72j/u"
-9*Z(91[
-d7"R/
+n#!#n
/`7*Z(
9#Z\74g
h)`7(i
/d='o$
m7$g/th
d70S&Tl
_d?'om
Fh=d7:D
m7#g/th
Gd?'om
/,U_/,
&d7x'l
/,T o,
Wd?'om
/,9#[)T
|W/,7;
/,9#[)T@
)98[=T
/d?'om
7i9#[?
Yk[-,
Gd?'om
j(d7 g
Od?'os
`7)j|h
/d9#Z>
/,9#[B
<J,,T,
k/d7:g
h'd9*[(7
.,9#WZ
/d9#[9
94-.,9#[~
(.,9#[a
(.,9#[1C
/d9#["
k/eC#f
/#9a/,
d?'OwU
/d?'Ow
$.,9#Z8C
h `1fw(
/d='?)
hd49#Z#
^.,9#Z>C
Y.,9#
Gd?'om
d?'sU4
9PT.,7;
/nne(Tz
9\@.,9#Z:C
h$h7,c
C.,9#[L7g
98}.,?
)TC.,{`
wd?'os
/d?'ow
/d91Z$
z.,9#[0?
hll73g
h d73g
9Pn.,9#Z8C
n.,9#[
wd?'s
/h7$gOo
<i9#W"
/,T|.,
/,T0p,
d98[.5
m77j|
/d1nW/
\-,76g
Od?'m
d9*[)Tp`,
) E-,z
A-,9#[57+
d9#Z6C
Gd?'om
cO9K,,
/,T(g,
#9+-,
'd7!g'}`
" `}jl
/#8H,,
/,C*[[?
/,C*[PC*[F?
0#8V/,
/,C*[\?
/#8s.,
/,9#Z"
/,="/(
.,9#[3
wd?'m
d?#+d5
Od?#od7+g
Od?#om
d?#;d5
/#8u.,
Gd?'om
j(`7 f
md91[<
)lE-,W
asj"9
!T{-,W
gd?'m
gd?'s
.,9#Z1C
/d9*[*C
/d9*[;TH
/nZ/(
j|Y/,
.,9#Z<C
/,9#[3
jj<9#[
)H~-,T0v
9*[)T4
/d9*[*C
9*[)T4
!Hy-,C
.,9#Z;T|
:/e7#f
%d?!?e?"?
j>d?"'eC*Z
k>dC"f
?d?"od5
d74 k}
tk.dC"
*#9=.,
"d91[$
.,9#n#
.,9#[7
d? 'YQ
/d98[6
h$d9*['T
nm-Up.,
Wd?'om
/,TD5,
od9#Z!T4<,
!d9*Z"
a9*Z.4
e?#'#8h/,
eC+[T8
]iJ"(X
j>d?"'
9#Z9T(%,
/m<.#9
nm.TtH,
9#Z)?+
a9#[FK"(,
eC+[~8#[b
9#Z)?+
9#Z)?+
"I#k#n
;d?!?J
)L--,T
-,TLK,
/,T@H,
d98Z<T
+d?#;d?'
+d?#?d?'
g#"\&
/,J"oX
jT$J"?#8j/,
/d?#Od
nm.T8x,
,m7)gO~
/e?&'d9#[
/mK%$
e?&'mK%?$
/mK%$
@#8u/,
W#9 -,
e7#fOu
/mJ%oX
$mJ%.X
8mJ%+Y
5mJ%+X
%dC$n#
$d?$-m
,m7)gO}
/e?&'d9#[
/mK%$
e?&'mK%?$
/mK%$
@#8u/,
W#9 -,
e7#fOu
/mJ%oX
$mJ%.X
8mJ%+Y
5mJ%+X
%dC$n#
$d?$-m
/d?"dC
e76f/x
/,9#["
d9#Z#T
9$:/,W~g
/d? ?dC,Z
Gd?'os
)\r-,C
)4r-,C
)ds-,C
)@l-,C
\0/,p/
`71c/}
)d?#7e
9X-/,C$g
-,Uh/,
_d?'m
Yfhh(?
d?!-dC(Z
md98[7L
d98Z$1
7n4g.le
!0?.,?+
%/,9#
9<#/,7
`d$Cj,
/J5bE.
/,,Z#,
`d$Cj,
/,Ub/,
Od?'m
gnd-T
d7+gOC
UlJ$-Y
P/,9#
9HQ/,9#
-#96/,
j)d?%-d=
U.dC"g
/,Uz(,
lK.X!2
g#8~/,
i`n;,5
e7<f/{
.#9Y.,
hbdK9n
7e?"-J
je?#-`
j,d? -m
9 @/,?
98B/,9#
hh<7(g/t
9$~/,7+
+`72[?
(K;c/m
e7=gGg
]l$?+'
h(d? wd
9X{/,W
9#[ 7+
z/,9#Z$C
9<{/,W
9#[ 7+
d?#'d5
d?#'d5
/#8=/,
/#8%/,
/8#[`9
d98Z0?+
Kd?$'d
9pr/,7#g
;d? -J
<81[&8
nk-C g
nk-A g
nk-G g
nk-E g
&a9#Z1
nm|WsI
9dh/,?
x#98.,
!LQ/,C
/d9#[<
/d9#[/L
/d9*[:?
/d9#[k?
h?d91[(L
d91[(L
d98Z$1
<a9#["
9(`/,?
/,9#[>
Cn`-T
d9*[`J
9(c/,7+
/d98g#
9Dl.,7
jz,98Q
d9#[&{
hb\9*
d7(b/|
Gd?'m
9*[:C*['C*Z5
/,U~/,
d98Z(76
!J9*[)
Od?'os
/,9#[v
wd?'os
0a9#[#6
Z<K%/l
/,|Y/,
%lJ%?X
kRKK%/,
,#9o/,
h$i7$fOz
Od?'os
d98Q7W8
/,K;g7C
?d7a?-
''}Z.,
?'}Z.,
/'}Z+,
''}Z.,
d?#?d5
7#9U-,
?'}Z.,
-}Z+,
''}Z.,
?'}Z.,
/'}Z+,
-}Z+,
d?#+d5
d?#+d5
d?#+d5
''}Z.,
?'}Z.,
''}Z.,
!HJ/,7
9,H/,7
/}Z+,
!\J/,7
9lK/,7
9$K/,7
j|h;-
#.d1g+
*/d1o#
/d9*Z>T
/,9#[;
/,9#[;
nY$C#c
ng%TL=
j,d? 'e7
/,9#[FT
+#8w/,
d9*Z9Tl
t.,98[e
/d? 'd7
d98Z>TL
h,d9#
/,9#[/1
%J9*[)
/,9#Z!T
ld? -#
j(d9#[O
h,d9#[Y?.
od9#[M
d9#Z#W
}48#[q
od7s-
*p//,W
Wd?'Os
98[39#[75
?d7a7-
Od?'qUD
/,rT,,
/,XT,,
/,@T,,
/,LR,,
/,\R,,
/,zR,,
/,(R,,
/,2O,,
/,vO,,
/,\O,,
/,HO,,
/,8N,,
/, N,,
/,rN,,
/,\N,,
/,LN,,
/,@N,,
/,6M,,
/,&M,,
/,|M,,
/,hM,,
/,XM,,
/,JM,,
/,8L,,
/,*L,,
/,|L,,
/,lL,,
/,fL,,
/,ZL,,
/,BL,,
/,<S,,
/,.S,,
/,pS,,
/,`S,,
/,VS,,
/,PH,,
/,fH,,
/,xH,,
/,*H,,
/,4H,,
/,DI,,
/,,T,,
/,TU,,
/,rU,,
/,$U,,
/,6U,,
/,ZI,,
/,NL,,
/,dI,,
/,vP,,
/,fP,,
/,LP,,
/,&W,,
/,vW,,
/,dW,,
/,(V,,
/,zV,,
/,dV,,
/,PV,,
/,BV,,
/,nQ,,
/,ZQ,,
/,,P,,
/,$Q,,
qW|'/pF
:zFLODgSPRzX[JnTWC
j^DGbR@C-
.-rJHK
vu2*hkG
47`QAB
twh]EF1
(=ef$7c`
:&lo&4ba
-.BbPS
65Zv\_|COL
%&.8fe
vLJIHmUV
03*>dg
pIIJ,;gd
!"~@NM
>=nXFE
8%mnl[GD> nm
.P"Jr8
Pu1gq}
UA)9v~h
;$aee"
;15bZ:8kT'/pF,"yH
]pi]**bP#$
G86tJ18Ei
pw5!ZF8(TM/3FP":H[iM
3m{!pl
UA)9v~'2{w5/ll;$aeaM*
N.,wM.,
/,qS.,SS.,x[-,
/,HS.,
R.,x[-,
P.,b[-,
[.,q[.,J[-,
/,QZ.,@Z.,
.,)Z-,
.,|Z-,
.,\Z-,
.,HZ-,
-, Y-,
-,pY-,
-,pY-,
-,[Y-,
-,[Y-,
/,Pp-,Dp-,
/,"C-,
C-,nX-,
/,VC-,
B-,nX-,
/,DS,,
/,6Q,,
#-,|J,,
P,,4&-,
/,rT,,
/,XT,,
/,@T,,
/,LR,,
/,\R,,
/,zR,,
/,(R,,
/,2O,,
/,vO,,
/,\O,,
/,HO,,
/,8N,,
/, N,,
/,rN,,
/,\N,,
/,LN,,
/,@N,,
/,6M,,
/,&M,,
/,|M,,
/,hM,,
/,XM,,
/,JM,,
/,8L,,
/,*L,,
/,|L,,
/,lL,,
/,fL,,
/,ZL,,
/,BL,,
/,<S,,
/,.S,,
/,pS,,
/,`S,,
/,VS,,
/,PH,,
/,fH,,
/,xH,,
/,*H,,
/,4H,,
/,DI,,
/,,T,,
/,TU,,
/,rU,,
/,$U,,
/,6U,,
/,ZI,,
/,NL,,
/,dI,,
/,vP,,
/,fP,,
/,LP,,
/,&W,,
/,vW,,
/,dW,,
/,(V,,
/,zV,,
/,dV,,
/,PV,,
/,BV,,
/,nQ,,
/,ZQ,,
/,,P,,
/,$Q,,
/,L+-,
/,4[,,0[,,,[,,H
/,HB,,
/,0},,
/,(|,,x
/,L|,,
/,h|,,@
/,@@,,
/,0C,,
/, C,,
/,hC,,
/,PC,,
/,p~,,\
/,ps,,<
/,HB,,
/,8B,,
/, B,,,
/,xB,,x
c/,Xc/,
x,,Xc/,
b/,\B,,
b/,}b/,
s,,xb/,
x,,|g/,{f/,
C,,tf/,
e/,HB,,
d/,Bd/,
j/,)j/,
A,,$j/,hj/,
C,,hj/,
h/,nh/,
A,,hh/,
o/,"r/,
p/,3w/,@@,,,w/,
u/,$A,,Xu/,
y/,tA,,
y/,oy/,
u,,hy/,
/,xn,,
A/,PA,,<A/,
J/,;J/,
x,,4J/,
I/,7R/,
@,,0R/,RQ/,
@,,LQ/,
V/,YU/,,@,,TU/,
X/,j^/,t@,,d^/,|]/,p~,,|]/,8\/,
u,,8\/,i#/,X@,,d#/,
"/,p~,,<"/,
!/,xn,,
!/,n!/,p~,,h!/,
/,HB,,
/,:'/,xn,,4'/,
&/,@@,,
$/,?$/,
x,,8$/,
+/,C+/,
*/,p*/,
l,,p*/,
)/,k./,
h,,d./,
-/,/-/,
h,,(-/,
-/,S-/,
,/,-,/,
s,,(,/,H,/,
7/,$h,,
7/,07/,
6/,4h,,
4/,q4/,
h,,l4/,
;/,f;/,
p,,X;/,
:/,N:/,xn,,H:/,
9/,W9/,\s,,P9/,
=/,Th,,
</,hh,,
</,$</,
x,,$</,P</,
B,,P</,
/,\B,,
/,HB,,
/,`h,,P
/,(|,,
/,,o,,
/,0},,
/,`o,,
/,lo,,
/,p~,,
/,Po,,
/,Ho,,
.,,n,,8
.,xn,,
., n,,8
.,xn,,0
.,`n,,
.,Dn,,H
.,(m,,
.,Xm,,
.,pm,,
.,@m,,p
.,Dn,,P
.,p~,,
., l,,
.,`l,,
.,Tl,,0
.,,n,,p
.,<s,,
.,(s,,
.,@m,,`
.,HB,,X
.,ps,,
.,\s,,
.,Ds,,d
.,ps,,,
.,xn,,l
.,4r,,|
.,hr,,,
.,\r,,(
.,xq,,h
.,0},,
.,Tr,,@
`.,Dr,,|`.,^g.,
q,,Xg.,
q,,`f.,
e.,(e.,
u,,(e.,Rd.,
q,,Ld.,ik.,HB,,dk.,
i.,Xi.,4q,,Xi.,
h., q,,\h.,
m.,xq,,
l.,'l.,
u,, l.,xl.,
u,,dl.,
s.,&s.,\q,, s.,
r.,Hq,,
r.,>r.,
u,,8r.,
p.,@@,,
p.,Lw.,
p,,Lw.,
v.,_u.,
y,,Xu.,Au.,
t.,|t.,
p,,|t.,[{.,
p,,T{., z.,Hq,, z.,Oz.,
h,,Hz.,
x.,0},,
x.,ox.,
u,,hx.,
~.,r~.,
x,,l~.,
p,,||.,vC.,
p,,pC.,
p,,<B.,
A.,8B,,
A.,jA.,@m,,dA.,RA.,
@.,+@.,ps,,
@.,(K.,4p,,
I.,0p,,
u,,|H.,ZH.,
s,,DH.,
O.,CO.,
u,,4N.,
L.,VL.,
u,,PL.,
S.,\p,,
R.,zQ.,
w,,tQ.,
V.,,w,,|V.,
U.,$w,,
[.,dw,,
[.,K[.,
w,,D[.,
Y.,Lw,,
^.,(z,,
s,,|^.,
].,:].,
s,,4].,r].,
s,,l].,
".,w!.,
v,,p!.,
'.,&'.,
u,, '.,
x,,T&.,
*.,xv,,
).,pv,,
).,}).,
y,,x).,^).,
u,,X).,
/.,Pv,,
.,HB,,`
.,@@,,
.,0u,,X
.,$u,,t
.,tu,,
.,HB,,
.,Du,,
-,$t,,X
-,ht,,
-,p{,,
-,T{,,
-,L{,,
-,H{,,
-,D{,,
-,@{,,
-,(z,,|
-,Tz,,
-,xq,,
-,,y,,L
-,xn,,
-,|y,,
-,\y,,
-,Ly,,
-,<x,,
-,\x,,
-,p~,,d
-,{f-,
~,,lf-,
l-,_q-,
~,,Lq-,Dq-,
p-,vp-,
~,,dp-,
w-,2u-, ~,,,u-,
u-,Eu-,
x,,@u-,
B,,<t-,[t-,
~,,Tt-,
{-,\x-,
~,,\x-,
~,,||-,
C-,p~,,<C-,|C-,P~,,|C-,
B-,RB-,`~,,LB-,
G-,Hq,,
D-,Hq,,
D-,~D-,
x,,xD-,HK-,
},,HK-,
I-,0},,
I-,MI-,
},,HI-,
M-,p},,
Q-,Dn,,
Q-,LV-,L},,LV-,
T-,0},,
[-,x[-,
w,,x[-,b[-,
w,,b[-,J[-,
w,,J[-,
Z-,lw,,
Z-,)Z-,
w,,)Z-,
w,,|Z-,\Z-,
w,,\Z-,HZ-,
w,,HZ-,
Y-, Y-,
w,, Y-,
Y-,pY-,
w,,pY-,[Y-,
w,,[Y-,
X-,nX-,
w,,nX-,NX-,
/,dI/,
_set_invalid_parameter_handler
%c%c%c%c%c%c%c%c%cMSSE-%d-server
.pdata
Argument domain error (DOMAIN)
Argument singularity (SIGN)
Overflow range error (OVERFLOW)
Partial loss of significance (PLOSS)
Total loss of significance (TLOSS)
The result is too small to be represented (UNDERFLOW)
Unknown error
_matherr(): %s in %s(%g, %g) (retval=%g)
Mingw-w64 runtime failure:
Address %p has no image-section
VirtualQuery failed for %d bytes at address %p
VirtualProtect failed with code 0x%x
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
CloseHandle
ConnectNamedPipe
CreateFileA
CreateNamedPipeA
CreateThread
DeleteCriticalSection
EnterCriticalSection
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetLastError
GetModuleHandleA
GetProcAddress
GetStartupInfoA
GetSystemTimeAsFileTime
GetTickCount
InitializeCriticalSection
LeaveCriticalSection
LoadLibraryW
QueryPerformanceCounter
ReadFile
RtlAddFunctionTable
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
SetUnhandledExceptionFilter
TerminateProcess
TlsGetValue
UnhandledExceptionFilter
VirtualAlloc
VirtualProtect
VirtualQuery
WriteFile
__C_specific_handler
__dllonexit
__getmainargs
__initenv
__iob_func
__lconv_init
__set_app_type
__setusermatherr
_acmdln
_amsg_exit
_cexit
_fmode
_initterm
_onexit
_unlock
calloc
fprintf
fwrite
malloc
memcpy
signal
sprintf
strlen
strncmp
vfprintf
KERNEL32.dll
msvcrt.dll
msvcrt.dll
Antivirus Signature
Bkav W32.AIDetectMalware.64
Lionic Trojan.Win32.CobaltStrike.4!c
tehtris Clean
DrWeb BackDoor.CobaltStrike.86
ClamAV Win.Trojan.CobaltStrike-9044898-1
CMC Clean
CAT-QuickHeal Trojan.CobaltStr.S17675256
ALYac Gen:Variant.Zusy.476946
Cylance unsafe
VIPRE Gen:Variant.Zusy.476946
Sangfor Trojan.Win32.CobaltStrike
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Gen:Variant.Zusy.476946
K7GW Trojan ( 0058fadf1 )
K7AntiVirus Trojan ( 0058fadf1 )
BitDefenderTheta Clean
VirIT Clean
Cyren W64/Agent.NDUI
Symantec Backdoor.Cobalt!gen1
Elastic Windows.Trojan.CobaltStrike
ESET-NOD32 a variant of Win64/CobaltStrike.Artifact.A
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win64.CobaltStrike.gen
Alibaba Trojan:Win32/CozyDuke.1012
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Gen:Variant.Zusy.476946
Tencent Trojan.Win64.Cobaltstrike.za
Sophos ATK/Cobalt-CC
F-Secure Heuristic.HEUR/AGEN.1344219
Baidu Clean
Zillya Clean
TrendMicro Backdoor.Win64.COBEACON.SMA
McAfee-GW-Edition BehavesLike.Win64.Trojan.dc
Trapmine Clean
FireEye Generic.mg.f8c994f9200f4155
Emsisoft Trojan.CobaltStrike (A)
SentinelOne Static AI - Malicious PE
Jiangmin Trojan.Generic.fsici
Webroot Clean
Avira HEUR/AGEN.1344219
MAX malware (ai score=82)
Antiy-AVL RiskWare/Win64.Artifact.a
Microsoft Backdoor:Win64/CobaltStrike.NP!dha
Gridinsoft Trojan.Win64.CobaltStrike.bot
Xcitium Clean
Arcabit Trojan.Zusy.D74712
ViRobot Clean
ZoneAlarm HEUR:Trojan.Win64.CobaltStrike.gen
GData Gen:Variant.Zusy.476946
Google Detected
AhnLab-V3 Trojan/Win64.CobaltStrike.R356638
Acronis Clean
McAfee Trojan-FSXF!F8C994F9200F
TACHYON Trojan/W64.CobaltStrike.288256
DeepInstinct MALICIOUS
VBA32 Trojan.Win64.CobaltStrike
Malwarebytes CobaltStrike.Trojan.Infiltration.DDS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Backdoor.Win64.COBEACON.SMA
Rising Backdoor.CobaltStrike/x64!1.D04A (CLASSIC)
Yandex Clean
Ikarus Trojan.Win64.Cobaltstrike
MaxSecure Trojan.Malware.300983.susgen
Fortinet W64/Agent.CY!tr
AVG Win64:HacktoolX-gen [Trj]
Cybereason malicious.d3ce29
Avast Win64:HacktoolX-gen [Trj]
No IRMA results available.