97e152b4d7b1d3965648b7394986e7f330310dfea336e835c5cc5a33ed4f80c5
Classification: Malicious
97e152b4d7b1d3965648b7394986e7f330310dfea336e835c5cc5a33ed4f80c5 is a malicious file sample. Linked to Cobalt Strike malware.
Detection summary
- 63 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: COBALT STRIKE (S0154)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Cobalt Strike | Triage | 2026-03-03 20:49:57 | 2026-03-03 20:49:57 | malicious-activity | S0154 Cobalt Strike |
Tags
cobaltstrike backdoor trojanSample information
- Filenames
- 97e152b4d7b1d3965648b7394986e7f330310dfea336e835c5cc5a33ed4f80c5
- MD5
79abfaab11b2c5de134c4bd2821f87b5- SHA-1
e1e4a230d2f6d62678bbeee2af9f226579b6b003- SHA-256
97e152b4d7b1d3965648b7394986e7f330310dfea336e835c5cc5a33ed4f80c5- SHA-512
accf6927244f498453e8743aa4585044d98cf43789aba17f62ad06fd693f4c76f2db5f82887413e4ba33334dbc5862c4737770204c03994aebfa8430a75762cf- First indexed
- 2026-03-03 20:49:57
- Last updated
- 2026-09-03 00:08:45
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Gen:Variant.Application.Mikey.108320 |
| AVG | Win64:Evo-gen [Trj] |
| AhnLab-V3 | Trojan/Win.Generic.C4447468 |
| Alibaba | Trojan:Win64/Shelma.2704696f |
| Antiy-AVL | Trojan/Win64.Shelma |
| Arcabit | Trojan.Application.Mikey.D1A720 |
| Avast | Win64:Evo-gen [Trj] |
| Avira | HEUR/AGEN.1318645 |
| BitDefender | Gen:Variant.Application.Mikey.108320 |
| Bkav | W64.AIDetectMalware |
| CAT-QuickHeal | Trojan.Win64RI.S20968137 |
| CTX | exe.trojan.shelma |
| ClamAV | Win.Malware.Shelma-9863151-0 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.MulDrop17.54984 |
| ESET-NOD32 | Win64/Rozena_AGen.BO trojan |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.Application.Mikey.108320 (B) |
| F-Secure | Heuristic.HEUR/AGEN.1318645 |
| Fortinet | W64/Agent.CE99!tr |
| GData | Gen:Variant.Application.Mikey.108320 |
| Detected | |
| Gridinsoft | Trojan.Win64.Wacatac.oa!s1 |
| Ikarus | Trojan.Win64.Rozena |
| Jiangmin | Trojan.Shelma.hys |
| K7AntiVirus | Riskware ( 0040eff71 ) |
| K7GW | Riskware ( 0040eff71 ) |
| Kaspersky | Trojan.Win64.Shelma.jxt |
| Kingsoft | malware.kb.a.932 |
| Lionic | Trojan.Win64.Shelma.tt31 |
| Malwarebytes | Trojan.CobaltStrike |
| MaxSecure | Trojan.Malware.133898145.susgen |
| McAfeeD | ti!97E152B4D7B1 |
| MicroWorld-eScan | Gen:Variant.Application.Mikey.108320 |
| Microsoft | Trojan:Win64/CobaltStrike.CG!MTB |
| Paloalto | generic.ml |
| Panda | Trj/GdSda.A |
| Rising | Trojan.Shelma!8.1A3D (TFE:5:Mw4doJkweT) |
| SUPERAntiSpyware | Trojan.Agent/Gen-Shelma |
| Sangfor | Trojan.Win32.Save.a |
| SentinelOne | Static AI - Suspicious PE |
| Skyhigh | BehavesLike.Win64.Injector.fh |
| Sophos | Troj/Cobalt-KM |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Trojan.Win64.Rozena.16002570 |
| Trapmine | malicious.moderate.ml.score |
| TrellixENS | GenericRXAA-AA!79ABFAAB11B2 |
| TrendMicro | Backdoor.Win64.COBEACON.YXGCCZ |
| TrendMicro-HouseCall | Backdoor.Win64.COBEACON.YXGCCZ |
| VBA32 | Trojan.Win64.Shelma |
| VIPRE | Gen:Variant.Application.Mikey.108320 |
| Varist | W64/ARisk.BA |
| ViRobot | Trojan.Win.Z.Shelma.364544.DUT |
| VirIT | Trojan.Win64.Genus.JAY |
| Webroot | W32.Malware.Gen |
| Yandex | Trojan.Shelma!Se62mB7Pb2E |
| Zillya | Trojan.Shelma.Win64.5223 |
| ZoneAlarm | Troj/Cobalt-KM |
| alibabacloud | Trojan:Win/Rozena_AGen.592fd585 |
| huorong | HVM:Backdoor/Mikey.a |