Crack

What is “HackTool.Win32.Cobalt.aim”?

Malware Removal

The HackTool.Win32.Cobalt.aim is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool.Win32.Cobalt.aim virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Network activity detected but not expressed in API logs

How to determine HackTool.Win32.Cobalt.aim?


File Info:

crc32: 46719D99
md5: 1bc12c94d44c3be938d8e60a6709daff
name: 1BC12C94D44C3BE938D8E60A6709DAFF.mlw
sha1: d9c8f8ff87a5167cf6a3b476964154b01caa9ddb
sha256: eb86c3f0afa27791f60270fdb97b4eed295b31735b6fb45c37a6503d0bf3511d
sha512: aa18e530985f92a937a409f2b7cf887f6c758cf3811542c26852587ebb5ef1fe49a30fbb7518a360e39ceca6379c8b4281126a596fb5170e98bbd715abbf184d
ssdeep: 6144:RMT9b2lNpjk4ldH1uOs5C8IkEB+y0tO4uHxoPjMdvNZRhu7Dpr2AuTVUC:STYpjkmJk1dEBoPCxI2zju7Dpr2AuTZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c)2006-2008 CHENGDU YIWO Tech Development Co., Ltd.
InternalName: ud
FileVersion: 1, 1, 0, 0
CompanyName: CHENGDU YIWO Tech Development Co., Ltd (YIWO Tech Ltd, for short).
ProductVersion: 1, 1, 0, 0
OriginalFilename: ud.exe
Translation: 0x0804 0x04b0

HackTool.Win32.Cobalt.aim also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 005693e61 )
LionicHacktool.Win32.Cobalt.3!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.46617737
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaHackTool:Win32/Cobalt.959c28bd
K7GWAdware ( 005693e61 )
Cybereasonmalicious.f87a51
CyrenW32/Trojan.GXPV-3573
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:HacktoolX-gen [Trj]
KasperskyHackTool.Win32.Cobalt.aim
BitDefenderTrojan.GenericKD.46617737
MicroWorld-eScanTrojan.GenericKD.46617737
TencentWin32.Hacktool.Cobalt.Ebrd
Ad-AwareTrojan.GenericKD.46617737
SophosMal/EncPk-APX
ComodoTrojWare.Win32.Agent.keczx@0
BitDefenderThetaGen:NN.ZexaF.34796.Iy0@aCVUEbkj
TrendMicroBackdoor.Win32.COBALT.YABGL
McAfee-GW-EditionBehavesLike.Win32.Ransomware.hh
FireEyeGeneric.mg.1bc12c94d44c3be9
EmsisoftTrojan.GenericKD.46617737 (B)
SentinelOneStatic AI – Suspicious PE
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojan:Win32/Bsymem.VS!MSR
GridinsoftTrojan.Heur!.02012021
ArcabitTrojan.Generic.D2C75489
ZoneAlarmHackTool.Win32.Cobalt.aim
GDataTrojan.GenericKD.46617737
AhnLab-V3Trojan/Win.Generic.R431055
Acronissuspicious
McAfeeGenericRXPF-WE!1BC12C94D44C
MAXmalware (ai score=80)
VBA32BScope.Trojan.Behavior.NewScheduledTask
MalwarebytesTrojan.Meterpreter
PandaTrj/GdSda.A
TrendMicro-HouseCallBackdoor.Win32.COBALT.YABGL
RisingTrojan.Generic@ML.90 (RDML:PFwfSfVDW9cuPYoM0DXNZw)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:HacktoolX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/HackTool.CobaltStrike.HxQBkqwA

How to remove HackTool.Win32.Cobalt.aim?

HackTool.Win32.Cobalt.aim removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment