Trojan.CobaltStrike.RK
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 13,198 |
| Threat Level: | 80 % (High) |
| Infected Computers: | 8 |
| First Seen: | April 17, 2026 |
| Last Seen: | June 9, 2026 |
| OS(es) Affected: | Windows |
Table of Contents
Analysis Report
General information
| Family Name: | Trojan.CobaltStrike.RK |
|---|---|
| Signature status: | Modified signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
40241419ba75196bf4b804d9b1aee8a8
SHA1:
a0683b298aaf1e43a230f162018067ea9eab239b
SHA256:
0AF20FA1E1A7A6C879B4B740233CF3499D9B6B7F33CE38DB6E011C2CED3866CD
File Size:
1.23 MB, 1233060 bytes
|
|
MD5:
c6ab466b8fefe4778cf81d746ab937bd
SHA1:
3b4d7330494b87b1140c8feb0bfd6d2f017f516c
SHA256:
40EB80DE4E2349C2953D3626830F804D158AE471EF797B6E796569415F1B6FB3
File Size:
1.25 MB, 1245048 bytes
|
|
MD5:
12756fbf6f991ed9c92064318622b766
SHA1:
46e50efca739a8defbc51f0be25ebea178f30381
SHA256:
B38D48A4D95A19B774D6929E18E0C363D8D6607241D88065CEC6CB2930EA82C1
File Size:
1.25 MB, 1252750 bytes
|
|
MD5:
a4d636c952bbf469c99104096fac87c2
SHA1:
654bffdd0cf766b49619701ba2978cf5e84338d4
SHA256:
0D99B04497CB75566DE6ADA802E35BC74A6E174ED8B1A4A276F0F51E745E9C55
File Size:
1.22 MB, 1220508 bytes
|
|
MD5:
96890ba7b35b3b5779d1a1749269f7ce
SHA1:
2c206884ceac4a54a5b7dbf40710314e5b7b799d
SHA256:
825F1599A87C8F15C9FECBF07C637C9D42F943CFA33099458FC6DEB2265DD2B1
File Size:
1.26 MB, 1257720 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have exports table
- File doesn't have security information
- File has TLS information
- File is 64-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Company Name |
|
| File Description |
|
| File Version |
|
| Internal Name |
|
| Legal Copyright |
|
| Original Filename |
|
| Product Name |
|
| Product Version |
|
File Traits
- big overlay
- fptable
- Installer Manifest
- Installer Version
- ntdll
- x64
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 896 |
|---|---|
| Potentially Malicious Blocks: | 34 |
| Whitelisted Blocks: | 841 |
| Unknown Blocks: | 21 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- CobaltStrike.RK
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
|