CobianRAT v1.0.40.7.exe

Classification: Malicious

CobianRAT v1.0.40.7.exe is a malicious file sample. Linked to Cobian Rat malware. Reported by 3 threat sources, last seen 2026-03-04.

Detection summary

  • 63 antivirus detections
  • 0 IDS alerts
  • 3 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: COBIAN RAT (S0338)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Cobianrat Triage 2026-03-04 10:49:54 2026-03-04 10:49:54 malicious-activity S0338 Cobian RAT
Generic Malware Hybrid-Analysis 2024-10-04 05:45:06 2024-10-04 06:49:07
CobianRAT MalwareBazaar Abuse.ch 2022-04-27 17:20:55 2022-04-27 17:20:55 malicious-activity S0338 Cobian RAT
Generic.Malware MalwareBazaar Abuse.ch 2022-04-27 17:20:55 2022-04-27 17:20:55 malicious-activity

Tags

windows-server-utility cobianrat

Sample information

Filenames
CobianRAT v1.0.40.7.exe
File type
application/x-dosexec
Size
1005568 bytes
MD5
0e89a13c623f26af0482d2b8d51d8b02
SHA-1
8bdef3070fbc759edfd43c7847a676e91be12c5a
SHA-256
1f2c145fc77049b9437c9aedfd8332be167246bc270d98c22deca902fc967563
SHA-512
d7fabfcea46081fb24ae5a06c75b097c7e451848a20d96b77dcf900863a561b4b8724120276bbdaebd6827cb88b8cfbb397c96107c9a328245f8a07bfb6f70ea
First indexed
2022-04-27 18:15:05
Last updated
2026-03-30 12:46:01

Antivirus detections

EngineDetection
ALYacTrojan.Downloader.Agent
APEXMalicious
AVGWin32:Malware-gen
AhnLab-V3Trojan/Win32.RatCobian.C2122846
AlibabaTrojanSpy:MSIL/Keylogger.250ababf
Antiy-AVLTrojan/Win32.AGeneric
ArcabitTrojan.MSIL.Bladabindi.1
AvastWin32:Malware-gen
AviraHEUR/AGEN.1375312
BitDefenderGen:Heur.MSIL.Bladabindi.1
BkavW32.AIDetectMalware.CS
CTXmalware (ai score=100)
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.c623f2
CylanceUnsafe
DeepInstinctMALICIOUS
DrWebTrojan.Packed2.42828
ESET-NOD32a variant of MSIL/Kryptik.ODA
Elasticmalicious (high confidence)
EmsisoftGen:Heur.MSIL.Bladabindi.1 (B)
F-SecureHeuristic.HEUR/AGEN.1375312
FireEyeGen:Heur.MSIL.Bladabindi.1
FortinetW32/Keylogger.CMQQ!tr
GDataGen:Heur.MSIL.Bladabindi.1
GoogleDetected
GridinsoftRansom.Win32.Bladabindi.sa
IkarusBackdoor.MSIL
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
KasperskyTrojan-Spy.MSIL.Keylogger.cmqq
Kingsoftmalware.kb.c.976
LionicTrojan.Win32.Keylogger.l!c
MalwarebytesGeneric.Crypt.Trojan.DDS
MaxSecureTrojan.Malware.10673657.susgen
McAfeeGenericRXBT-EZ!0E89A13C623F
McAfeeDReal Protect-LS!0E89A13C623F
MicroWorld-eScanGen:Heur.MSIL.Bladabindi.1
MicrosoftTrojanSpy:Win32/Skeeyah.A!rfn
NANO-AntivirusTrojan.Win32.Keylogger.emojwm
Paloaltogeneric.ml
PandaTrj/CI.A
RisingMalware.Obfus/[email protected] (RDM.MSIL2:XUc/VgfyR77VmaCZEI9+Ng)
SangforSpyware.Msil.KeyLogger.V5ae
SentinelOneStatic AI - Malicious PE
SkyhighGenericRXBT-EZ!0E89A13C623F
SophosMal/Generic-R
SymantecML.Attribute.HighConfidence
TencentMalware.Win32.Gencirc.114cc21e
Trapminemalicious.high.ml.score
TrendMicroTROJ_GEN.R002C0DEK24
TrendMicro-HouseCallTROJ_GEN.R002C0DEK24
VBA32TScope.Trojan.MSIL
VIPREGen:Heur.MSIL.Bladabindi.1
VaristW32/Risk.CPFG-3936
VirITTrojan.Win32.GenusT.DUVW
WebrootW32.Trojan.Cobianrat
XcitiumMalware@#2djhv38244w9x
YandexTrojan.Agent!S6dcSkF03og
ZillyaTrojan.Keylogger.Win32.54854
ZoneAlarmTrojan-Spy.MSIL.Keylogger.cmqq
alibabacloudTrojan:MSIL/Kryptik.FWG
huorongTrojanDownloader/MSIL.Pstinb.a
tehtrisGeneric.Malware

Process list

NameCommand line
CobianRATv1.0.40.7.exe
fondue.exe/enable-feature:NetFx3 /caller-name:mscoreei.dll
OptionalFeatures.EXE/enable-feature:NetFx3 /caller-name:mscoreei.dll