Trojan:XML/CobaltStrike
This is a detection for the VBA file with XML content (commonly used in Microsoft Office files such as Excel, Word, and PowerPoint). The XML content is responsible for downloading the Cobalt Strike loader from the intended malicious URL.
Cobalt Strike is a commercially available penetration testing tool used for adversary simulation. It’s also known for being used by threat actors in various campaigns and found in many pre-ransomware incidents.
For information about Cobalt Strike and other human-operated malware campaigns, read these blog posts:
HackTool:Win64/CobaltStrike
This is a detection for Cobalt Strike Beacon, which is a software component that gets deployed in target devices and allows an attacker remote access to the device to perform various tasks.
HackTool:Win32/CobaltStrike
This is a detection for Cobalt Strike Beacon, which is a software component that gets deployed in target devices and allows an attacker remote access to the device to perform various tasks.
Backdoor:Win64/CobaltStrike
This is a detection for Cobalt Strike Beacon, which is a software component that gets deployed in target devices and allows an attacker remote access to the device to perform various tasks.
Backdoor:Win32/CobaltStrike
This is a detection for Cobalt Strike Beacon, which is a software component that gets deployed in target devices and allows an attacker remote access to the device to perform various tasks.
Behavior:Win32/CobaltStrike
Behavior:Win32/CobaltStrike detects various generic behaviors exhibited by CobaltStrike Beacon.
Trojan:Win32/Cobaltstrike
This is a detection for Cobalt Strike Beacon, which is a software component that gets deployed in target devices and allows an attacker remote access to the device to perform various tasks.
Trojan:Win64/Cobaltstrike
This is a detection for Cobalt Strike Beacon, which is a software component that gets deployed in target devices and allows an attacker remote access to the device to perform various tasks.
TrojanDownloader:Win32/CobaltStrike
This threat downloads and installs other programs, including other malware, onto your PC without your consent.
TrojanDownloader:Win32/CobaltStrike is a trojan that downloads and installs the Cobalt Strike beacon.
TrojanDownloader:PowerShell/CobaltStrike
This is a detection for the PowerShell script responsible for downloading the Cobalt Strike loader from an .onion website or other intended malicious URL.
Cobalt Strike is a commercially available penetration testing tool used for adversary simulation. It’s also known for being used by threat actors in various campaigns and found in many pre-ransomware incidents.
Read the following blogs for details: