e6102303824f7c9ebd58747802eeb704cbe5188879bd24a310ed96e92640cc52.exe
Classification: Malicious
e6102303824f7c9ebd58747802eeb704cbe5188879bd24a310ed96e92640cc52.exe is a malicious file sample. Linked to Cobalt Strike malware.
Detection summary
- 57 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 1 contacted hosts
- 1 DNS requests
MITRE ATT&CK associations
Malware families: COBALT STRIKE (S0154)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2026-04-28 19:45:03 | 2026-04-28 19:45:03 | ||
| Cobalt Strike | Triage | 2026-04-28 19:35:25 | 2026-04-28 19:35:25 | malicious-activity | S0154 Cobalt Strike |
Tags
malicious cobaltstrike backdoor trojanSample information
- Filenames
- e6102303824f7c9ebd58747802eeb704cbe5188879bd24a310ed96e92640cc52.exe, e6102303824f7c9ebd58747802eeb704cbe5188879bd24a310ed96e92640cc52.bin
- File type
- PE32+ executable for MS Windows 5.02 (GUI), x86-64 ...
- MD5
4c732597aeecfc5a862fff42ce1ead75- SHA-1
bc21694ae14d9f7484080badcd54cefd4bbceee7- SHA-256
e6102303824f7c9ebd58747802eeb704cbe5188879bd24a310ed96e92640cc52- First indexed
- 2026-04-28 19:35:25
- Last updated
- 2026-09-02 17:37:25
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Gen:Variant.Application.Mikey.108320 |
| AVG | Win64:Evo-gen [Trj] |
| AhnLab-V3 | Trojan/Win.Generic.C4447468 |
| Alibaba | Trojan:Win64/Shelma.2704696f |
| Antiy-AVL | Trojan/Win64.Shelma |
| Arcabit | Trojan.Application.Mikey.D1A720 |
| Avast | Win64:Evo-gen [Trj] |
| Avira | HEUR/AGEN.1318645 |
| BitDefender | Gen:Variant.Application.Mikey.108320 |
| Bkav | W64.AIDetectMalware |
| CAT-QuickHeal | Trojan.Win64RI.S20968137 |
| CTX | exe.unknown.mikey |
| ClamAV | Win.Malware.Shelma-9863151-0 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.MulDrop17.54984 |
| ESET-NOD32 | Win64/Rozena_AGen.BO trojan |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.Application.Mikey.108320 (B) |
| F-Secure | Heuristic.HEUR/AGEN.1318645 |
| Fortinet | W64/Agent.CE99!tr |
| GData | Gen:Variant.Application.Mikey.108320 |
| Detected | |
| Gridinsoft | Trojan.Win64.Wacatac.oa!s1 |
| Jiangmin | Trojan.Shelma.hys |
| K7AntiVirus | Trojan ( 006dab901 ) |
| K7GW | Trojan ( 006dab901 ) |
| Kaspersky | Trojan.Win64.Shelma.jxt |
| Kingsoft | malware.kb.a.932 |
| Lionic | Trojan.Win64.Shelma.tt31 |
| Malwarebytes | Trojan.CobaltStrike |
| MaxSecure | Trojan.Malware.665969103.susgen |
| McAfeeD | Trojan:Win/Cobaltstrike.VYU |
| MicroWorld-eScan | Gen:Variant.Application.Mikey.108320 |
| Microsoft | Trojan:Win64/CobaltStrike.CG!MTB |
| Paloalto | generic.ml |
| Panda | Trj/GdSda.A |
| Rising | Trojan.Shelma!8.1A3D (TFE:5:Mw4doJkweT) |
| SUPERAntiSpyware | Trojan.Agent/Gen-Shelma |
| Sangfor | Trojan.Win32.Save.a |
| SentinelOne | Static AI - Suspicious PE |
| Sophos | Troj/Cobalt-KM |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Trojan.Win64.Rozena.16002570 |
| Trapmine | malicious.moderate.ml.score |
| TrellixENS | GenericRXAA-AA!4C732597AEEC |
| VIPRE | Gen:Variant.Application.Mikey.108320 |
| Varist | W64/ARisk.BA |
| VirIT | Trojan.Win64.Genus.JAY |
| Webroot | W32.Malware.Gen |
| Yandex | Trojan.Shelma!Se62mB7Pb2E |
| Zillya | Trojan.Shelma.Win64.5223 |
| ZoneAlarm | Troj/Cobalt-KM |
| alibabacloud | Trojan:Win/Rozena_AGen.592fd585 |
| huorong | HVM:Backdoor/Mikey.a |