Classification: Malicious
CobianRAT v1.0.40.7.exe is a malicious file sample. Linked to Cobian Rat malware. Reported by 3 threat sources, last seen 2026-03-04.
Detection summary
- 63 antivirus detections
- 0 IDS alerts
- 3 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Cobianrat |
Triage |
2026-03-04 10:49:54 |
2026-03-04 10:49:54 |
malicious-activity
|
S0338 Cobian RAT
|
| Generic Malware |
Hybrid-Analysis |
2024-10-04 05:45:06 |
2024-10-04 06:49:07 |
|
|
| CobianRAT |
MalwareBazaar Abuse.ch |
2022-04-27 17:20:55 |
2022-04-27 17:20:55 |
malicious-activity
|
S0338 Cobian RAT
|
| Generic.Malware |
MalwareBazaar Abuse.ch |
2022-04-27 17:20:55 |
2022-04-27 17:20:55 |
malicious-activity
|
|
Tags
windows-server-utility
cobianrat
Sample information
- Filenames
- CobianRAT v1.0.40.7.exe
- File type
- application/x-dosexec
- Size
- 1005568 bytes
- MD5
0e89a13c623f26af0482d2b8d51d8b02
- SHA-1
8bdef3070fbc759edfd43c7847a676e91be12c5a
- SHA-256
1f2c145fc77049b9437c9aedfd8332be167246bc270d98c22deca902fc967563
- SHA-512
d7fabfcea46081fb24ae5a06c75b097c7e451848a20d96b77dcf900863a561b4b8724120276bbdaebd6827cb88b8cfbb397c96107c9a328245f8a07bfb6f70ea
- First indexed
- 2022-04-27 18:15:05
- Last updated
- 2026-03-30 12:46:01
Antivirus detections
| Engine | Detection |
| ALYac | Trojan.Downloader.Agent |
| APEX | Malicious |
| AVG | Win32:Malware-gen |
| AhnLab-V3 | Trojan/Win32.RatCobian.C2122846 |
| Alibaba | TrojanSpy:MSIL/Keylogger.250ababf |
| Antiy-AVL | Trojan/Win32.AGeneric |
| Arcabit | Trojan.MSIL.Bladabindi.1 |
| Avast | Win32:Malware-gen |
| Avira | HEUR/AGEN.1375312 |
| BitDefender | Gen:Heur.MSIL.Bladabindi.1 |
| Bkav | W32.AIDetectMalware.CS |
| CTX | malware (ai score=100) |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cybereason | malicious.c623f2 |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.Packed2.42828 |
| ESET-NOD32 | a variant of MSIL/Kryptik.ODA |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Heur.MSIL.Bladabindi.1 (B) |
| F-Secure | Heuristic.HEUR/AGEN.1375312 |
| FireEye | Gen:Heur.MSIL.Bladabindi.1 |
| Fortinet | W32/Keylogger.CMQQ!tr |
| GData | Gen:Heur.MSIL.Bladabindi.1 |
| Google | Detected |
| Gridinsoft | Ransom.Win32.Bladabindi.sa |
| Ikarus | Backdoor.MSIL |
| K7AntiVirus | Riskware ( 0040eff71 ) |
| K7GW | Riskware ( 0040eff71 ) |
| Kaspersky | Trojan-Spy.MSIL.Keylogger.cmqq |
| Kingsoft | malware.kb.c.976 |
| Lionic | Trojan.Win32.Keylogger.l!c |
| Malwarebytes | Generic.Crypt.Trojan.DDS |
| MaxSecure | Trojan.Malware.10673657.susgen |
| McAfee | GenericRXBT-EZ!0E89A13C623F |
| McAfeeD | Real Protect-LS!0E89A13C623F |
| MicroWorld-eScan | Gen:Heur.MSIL.Bladabindi.1 |
| Microsoft | TrojanSpy:Win32/Skeeyah.A!rfn |
| NANO-Antivirus | Trojan.Win32.Keylogger.emojwm |
| Paloalto | generic.ml |
| Panda | Trj/CI.A |
| Rising | Malware.Obfus/[email protected] (RDM.MSIL2:XUc/VgfyR77VmaCZEI9+Ng) |
| Sangfor | Spyware.Msil.KeyLogger.V5ae |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | GenericRXBT-EZ!0E89A13C623F |
| Sophos | Mal/Generic-R |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Malware.Win32.Gencirc.114cc21e |
| Trapmine | malicious.high.ml.score |
| TrendMicro | TROJ_GEN.R002C0DEK24 |
| TrendMicro-HouseCall | TROJ_GEN.R002C0DEK24 |
| VBA32 | TScope.Trojan.MSIL |
| VIPRE | Gen:Heur.MSIL.Bladabindi.1 |
| Varist | W32/Risk.CPFG-3936 |
| VirIT | Trojan.Win32.GenusT.DUVW |
| Webroot | W32.Trojan.Cobianrat |
| Xcitium | Malware@#2djhv38244w9x |
| Yandex | Trojan.Agent!S6dcSkF03og |
| Zillya | Trojan.Keylogger.Win32.54854 |
| ZoneAlarm | Trojan-Spy.MSIL.Keylogger.cmqq |
| alibabacloud | Trojan:MSIL/Kryptik.FWG |
| huorong | TrojanDownloader/MSIL.Pstinb.a |
| tehtris | Generic.Malware |
Process list
| Name | Command line |
| CobianRATv1.0.40.7.exe | |
| fondue.exe | /enable-feature:NetFx3 /caller-name:mscoreei.dll |
| OptionalFeatures.EXE | /enable-feature:NetFx3 /caller-name:mscoreei.dll |