Threat Database Trojans Trojan.CobaltStrike.HM

Trojan.CobaltStrike.HM

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 25,460
Threat Level: 80 % (High)
Infected Computers: 90
First Seen: June 5, 2025
Last Seen: April 23, 2026
OS(es) Affected: Windows

The detection of Trojan.CobaltStrike.HM on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operational mechanisms, symptoms of infection, and most importantly, a step-by-step guide on how to remove it from your system.

What Is Trojan.CobaltStrike.HM?

Trojan.CobaltStrike.HM is identified as a Trojan-type threat. Trojans are malicious programs that can sneak onto your computer and perform a variety of harmful actions. They are often disguised as legitimate software, making them difficult to detect. The name Trojan.CobaltStrike.HM suggests it may be related to or utilize tactics similar to those of Cobalt Strike, a known tool used for penetration testing and potentially for malicious activities by attackers. However, without specific details, it's crucial to understand the general behavior of Trojans and how they can affect your system.

How Trojan.CobaltStrike.HM Operates

Trojan-type threats like Trojan.CobaltStrike.HM typically operate by gaining unauthorized access to a computer system. Once inside, they can perform a variety of malicious actions, including but not limited to, stealing sensitive information, installing additional malware, providing a backdoor for remote access by an attacker, and disrupting system operations. These threats can spread through various means, such as opening malicious email attachments, downloading software from untrusted sources, or visiting compromised websites.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely depending on the specific goals of the malware. Common indicators include unusual system behavior, such as unexpected pop-ups, slow system performance, or programs starting and stopping automatically. You might also notice changes in your system settings or find unfamiliar programs installed on your computer. Sometimes, the infection may not display any noticeable symptoms, making it difficult to detect without proper scanning tools.

How to Remove Trojan.CobaltStrike.HM

  1. Enter Safe Mode with Networking: This will help prevent the malware from spreading or causing further damage while you're connected to the internet for updates and downloads.
  2. Perform a Full Scan with a Reputable Tool: Utilize a trusted anti-malware program, such as SpyHunter, to scan your system thoroughly. Ensure your tool is updated with the latest definitions to improve detection and removal capabilities.
  3. Uninstall Suspicious Programs: Go through your installed programs and remove any that you don't recognize or that were installed without your knowledge.
  4. Reset Your Browsers: Resetting browsers like Chrome, Firefox, or Edge can help remove any malicious extensions or settings that the Trojan might have altered. This can often be done through the browser's settings or options menu.
  5. Reboot and Re-scan: After taking the above steps, reboot your system and perform another full scan to ensure that the threat has been completely removed. Repeat this process if necessary until no threats are detected.

Conclusion

Removing Trojan.CobaltStrike.HM requires careful and methodical steps to ensure your system is thoroughly cleaned and protected. It's also crucial to adopt preventive measures to avoid future infections, such as keeping your operating system and software up to date, using strong antivirus software, being cautious with emails and downloads, and regularly backing up your important data. By understanding the nature of Trojan threats and taking proactive steps, you can significantly enhance your computer's security and protect your personal information from potential harm.

Analysis Report

General information

Family Name: Trojan.CobaltStrike.HM
Signature status: No Signature

Known Samples

MD5: a0a35f5017ff1dd212c4aefe9c780c3b
SHA1: ced67d48d8415beeb2313f6615acabe95823118c
File Size: 1.27 MB, 1269248 bytes
MD5: 33db4317e0309793f8e1024f63391335
SHA1: 8be8a88582379d57d14c7b507c3488bfebc399dc
File Size: 1.27 MB, 1271296 bytes
MD5: 84312231c2708ffc8617e6fcf063d7bd
SHA1: 08af686b2e41d2cfa6d45981d68ff8421c0b0e4d
File Size: 1.58 MB, 1575936 bytes
MD5: be939fef684c9a388215eab7f9a3ac42
SHA1: e8ef1b51fde7bab6f0ffb5a70f59fd34de8a54a4
File Size: 1.12 MB, 1123840 bytes
MD5: 3a09d8a483930e52b360765ab7c06a0f
SHA1: bd4f843e3cef9dc3f43d6901fdb995923826078a
File Size: 1.28 MB, 1281024 bytes
Show More
MD5: d2b1e1c3b3acd1695041f9fb9ee8059c
SHA1: 3fa8d091fb1444200a0bc9aba067f087a971aa30
File Size: 1.40 MB, 1403392 bytes
MD5: 76f3f8f4f55b4b3a61530be3d746aca2
SHA1: cc818813dc3a3faba918f34ad2b87edfbff22767
File Size: 1.40 MB, 1395200 bytes
MD5: 98ded928ec78a9e6ca5039aeeb9a63c3
SHA1: 6d4e4d691788e2389cf0c67e1d209a5463d2b084
File Size: 1.43 MB, 1432064 bytes
MD5: 659189d273844c010664156769af9d83
SHA1: f4c953ce707a778b22fa37ed9fbed0d3f81ad513
File Size: 1.32 MB, 1323008 bytes
MD5: 77438729704a8a8d0138e56b799867de
SHA1: d537ef004728776d4347f721a87d631b354c07cd
File Size: 2.06 MB, 2059264 bytes
MD5: 99b8dd62bda73ca629d024d4a63be2a9
SHA1: 739c745feacb5416543b4106239e24435224fbff
File Size: 1.42 MB, 1421824 bytes
MD5: ae84caaa3270f0de6e52b20b2d08097f
SHA1: c7c711bcefe09d2484dd66e4946a48c6978d186f
File Size: 2.04 MB, 2040832 bytes
MD5: e0bf8b0e331090ef54fcd42fdfc153f7
SHA1: 3365f8790603dd2ee386ab4566ef80e6cf634065
File Size: 1.12 MB, 1121792 bytes
MD5: f98bb6d1e4760d3feaf3d1a3ffa91818
SHA1: 24d4c3989aed95af0a0bdd371d5357be85e576e2
SHA256: 5C93AE7394DF987905C32DED33EBB9096AE9051B61D886C7C9ACCFA822B29BA7
File Size: 1.37 MB, 1373696 bytes
MD5: 191cbfd6af39b7edb4f877798d109067
SHA1: 949fe881c46eb0f322742882bc782dacbeae5d46
SHA256: D19F9627CBDB2A002101133C020948237A2837B8FFD5136B8399E61B9735BBA1
File Size: 1.90 MB, 1895936 bytes
MD5: 7c120de14bd80b54675860213b4d5456
SHA1: de1c22db4024535d411b823e528bd349f75ef5d8
SHA256: C84A9C9705196060C03B2BF69ED9F4162861567CE905749A818AFBDC36F8FF09
File Size: 994.82 KB, 994816 bytes
MD5: 7f9422d84461ed7bdec09eea5ac42cb0
SHA1: fdd7f2f372758116bb82304c45ac53cd3f559cf4
SHA256: ABF4654E72EB7B1E8C6FF1B32C4BA94B5A68C1024ECB8E66F731295B50EDBE72
File Size: 1.18 MB, 1180672 bytes
MD5: 771d87eec82aeeef3b2466f7652d0b1a
SHA1: 4075aa1cd4aa999425071910530360821980b49f
SHA256: A22B65D14B98501D11D6C32F19A3D1FEF5A08506435D7315F912F1D27570D038
File Size: 968.19 KB, 968192 bytes
MD5: 06fa8961d5d88264220706fc4cb09403
SHA1: d484aa13f94061d056490b9f01ca9cf14b3d30fa
SHA256: 81F11017F192837CE00621B27ACA13F9A2FF0245F40D4797E26F4B8C26E60ABA
File Size: 1.39 MB, 1390080 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description
  • Sxs Tracing Tool
  • winrs
File Version
  • 10.0.19041.3636 (WinBuild.160101.0800)
  • 10.0.19041.1 (WinBuild.160101.0800)
Internal Name
  • sxstrace.exe
  • winrs.exe
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename
  • sxstrace.exe
  • winrs.exe
Product Name Microsoft® Windows® Operating System
Product Version
  • 10.0.19041.3636
  • 10.0.19041.1

File Traits

  • HighEntropy
  • No Version Info
  • x64

Block Information

Total Blocks: 6,608
Potentially Malicious Blocks: 3,207
Whitelisted Blocks: 2,812
Unknown Blocks: 589

Visual Map

? 0 0 0 x 0 x 0 x x x ? ? x ? x x x x x x 0 x ? 0 x 0 x x x x x x x x 0 0 0 x ? 0 x x 0 0 0 ? 0 x ? ? x x 0 x ? x x ? ? ? x ? 0 x x x x x x x 0 0 x x x x 0 0 ? 0 x x x x x x x x 0 0 x ? x x x x x x x 0 0 x x x x x 0 0 0 0 x x x x 0 0 0 x 0 0 x 0 x 0 0 x 0 x 0 0 x 0 x 0 0 0 ? x x ? x x 0 0 0 0 x ? x 0 x 0 x ? 0 0 0 0 x x x x x x x x x 0 x 0 0 x 0 x 0 x 0 0 x 0 x 0 x 0 0 x 0 x x x 0 ? x x 0 x 0 0 x 0 x x 0 0 x x ? 0 x x x 0 x x x x x x x ? 0 0 0 0 x x x 0 x x 0 x ? ? ? x 0 0 0 ? x 0 x x 0 x ? ? ? x 0 x 0 x x x 0 0 x x ? 0 x 0 0 x 0 0 x x x x 0 x ? 0 x x x x 0 ? x x x x x 0 x x x x x x ? 0 ? 0 x 0 0 ? x 0 x x ? x 0 0 x 0 x x x x x ? x 0 0 x x x x x x x 0 x ? 0 0 0 0 x 0 x 0 0 x x x x x x x x 0 x x x x x 0 x ? x x x 0 0 x x x x x ? 0 x 0 0 x 0 0 x x x x 0 0 x x 0 x x x x x 0 x 0 ? x x ? x ? x ? x ? 0 x x 0 x x x 0 0 x x x x 0 0 0 x x x x ? x x x x x 0 x 0 x 0 x x 0 x x 0 x x x 0 0 x x x 0 0 x 0 0 x x x x x 0 x x 0 x x x 0 x x 0 0 0 x x x x x 0 0 0 0 0 x 0 x x x x x 0 0 ? x x 0 x 0 0 0 ? 0 x x 0 x 0 x ? x x x x x 0 x x x x x x x x x 0 x x x 0 0 0 0 0 ? 0 x x 0 x x ? 0 0 0 x 0 x x ? 0 x x 0 0 0 0 0 0 x 0 x 0 x x x x x 0 ? x ? x x x x 0 x 0 x 0 x x 0 x x ? x x x 0 x x x x 0 ? x x x x 0 x x x x x 0 x 0 x x 0 0 x x x x x x x x 0 x x 0 x x x 0 x x x 0 x x x x x x x x x 0 x 0 x x x x x 0 0 x x x 0 x 0 x x x x 0 x ? 0 x x 0 x x ? 0 ? x x 0 x x x x x x x x x 0 ? x ? x x x x 0 x x x 0 x x x ? 0 x 0 x x x x x ? x x x x 0 x 0 x x 0 x 0 x x 0 x 0 x x 0 x 0 x x x x ? x 0 x 0 0 0 x x 0 0 x 0 0 x ? 0 x x x x ? 0 x 0 x x x x x ? x ? ? ? x ? x x 0 x x 0 x 0 x x x 0 0 x x x 0 0 0 x x x x 0 x x x 0 x x x 0 x x x x x x 0 0 0 x 0 x x x x 0 0 x x x 0 0 x x 0 0 0 0 0 x x x x 0 x x 0 x x x 0 0 x x 0 x x x x ? 0 x x 0 x x x x x x x 0 x x 0 x ? x x x 0 x x 0 x x x x x 0 ? x ? x x x x 0 x ? x 0 x x ? 0 x 0 x x x x x ? 0 ? x x ? x x 0 0 x x x x 0 ? 0 ? x x ? 0 0 x 0 x 0 x ? x x x 0 0 x x x x 0 x x x ? x x x 0 ? x x 0 0 ? x ? ? ? x x x x ? x 0 x 0 ? 0 x 0 0 x x 0 x 0 x x x 0 ? 0 0 x 0 x x x x x ? x 0 x ? x x x x x x x x 0 0 ? x x 0 x 0 x 0 x x 0 x x x 0 0 0 x x x 0 x ? 0 0 x 0 0 x x 0 0 0 x x x 0 x x x x ? ? ? x x 0 x ? x 0 x x x x x 0 x x x ? 0 x x 0 x x x x x x 0 x 0 ? ? x x x ? 0 0 ? 0 x 0 x x ? 0 0 0 0 x x ? x x x 0 x x 0 x ? 0 x x x 0 x x 0 x x 0 ? x x x ? 0 x 0 x x 0 x x x x 0 x 0 x 0 0 0 x 0 x x 0 0 x 0 ? x x 0 0 x 0 0 x 0 ? x ? 0 0 0 0 0 0 0 ? x 0 x 0 x x x 0 0 ? x 0 x x x 0 0 ? x x 0 0 0 x x 0 x 0 x x 0 0 x 0 x x 0 x x x 0 x x x x x 0 x ? x 0 x x ? x 0 x x ? x 0 ? 0 0 0 0 x 0 x x 0 x 0 x 0 0 x x 0 0 x x x x 0 ? x x x 0 x x x x 0 x 0 x ? ? x 0 x 0 x 0 0 x x x 0 0 0 ? ? x 0 0 0 0 x 0 x 0 0 0 ? ? 0 x x x 0 x 0 x x x 0 0 x x x x 0 ? 0 x x x x x 0 x x 0 ? 0 x x x 0 0 x x 0 0 x x x x x x 0 0 x x 0 0 0 ? ? 0 ? 0 0 0 0 x 0 x x 0 x 0 0 x 0 0 0 0 x 0 x 0 0 0 ? x x 0 ? ? 0 0 ? x x x 0 x ? x x 0 0 x x x x x 0 x x x 0 x ? x 0 x x 0 x x x x x 0 x 0 x x 0 0 0 x x x x 0 0 x x x x 0 x x 0 x 0 ? ? x x x 0 x 0 x x 0 x x x x x 0 0 0 ? 0 x x 0 x 0 ? 0 x 0 x x 0 0 x x x x ? 0 x x 0 0 ? 0 x x 0 0 x x x x 0 x x x x 0 x x x x x x 0 x 0 x 0 x x x x x x x x x 0 x x ? 0 x ? 0 0 x x x x x x x x x x x 0 0 x x 0 x x x x x 0 1 x x x x x x x 0 x 0 x x x 0 x x x x x x 0 0 0 0 0 0 0 0 ? x 0 x x 0 x 0 0 x x x x x x x x 0 x x 0 0 x x 0 0 x ? x ? x x 0 x ? ? x 0 x ? x x x ? x 0 0 0 x 0 x x x x 0 x x x x 0 ? x x 0 0 ? 0 x x x x x x x x 0 x 0 x x x x 0 x ? 0 0 0 0 x ? x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x x x 0 x x x x 0 x x 0 x x x 0 x 0 x x x 0 x x x x x 0 x 0 x 0 0 x x 0 0 x x x x 0 x x 0 x x 0 x x x x x x ? x 0 x 0 0 0 x x ? 0 x 0 0 x 0 ? 0 x 0 0 x 0 x x x x x x 0 x x x 0 ? 0 x 0 0 x 0 ? 0 x 0 0 x 0 x ? x 0 x 0 0 x 0 0 0 x x ? ? 0 x 0 0 x 0 x ? x x x 0 x 0 0 x x 0 0 x x x x x 0 ? 0 x 0 0 x 0 x 0 0 ? ? 0 0 0 0 x x x x x x x x 0 0 x x ? x x 0 x 0 x x x x x x x 0 0 0 0 x x x x 0 x ? x 0 x x x x 0 x x ? x x x x 0 x x x 0 x x 0 x x 0 x x 0 0 x 0 x x 0 x x x 0 0 x x x 0 x x 0 x 0 x x x x x 0 x 0 0 0 0 x x x 0 x 0 0 x x 0 x x x x x x x x x x 0 x x x 0 x 0 x 0 x ? 0 0 ? x 0 0 x 0 x x x x 0 x 0 x x x 0 0 ? x 0 x x x x x 0 x x 0 x 0 x x x 0 x ? x 0 x x 0 ? 0 0 0 ? x x x x x ? 0 0 0 0 ? ? 0 ? x 0 x 0 x x x x 0 0 x 0 x x x x 0 0 x 0 x 0 x x x x 0 0 x x x 0 x ? x 0 x 0 0 x 0 0 ? ? x x x x x ? x 0 x x x 0 x x x x 0 ? x 0 x x x x ? x x ? x ? 0 ? 0 x x x 0 ? x 0 ? 0 x 0 x ? x x 0 x x x x x 0 x 0 x x ? x x 0 ? x x ? x 0 x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • CobaltStrike.HM
  • CobaltStrike.SVA
  • CobaltStrike.UJ
  • Kryptik.DVM
  • Kryptik.DVN
Show More
  • Kryptik.DVO

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState

Trending

Most Viewed

Loading...