Crack

About “HackTool:Win32/CobaltStrike!pz” infection

Malware Removal

The HackTool:Win32/CobaltStrike!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/CobaltStrike!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine HackTool:Win32/CobaltStrike!pz?


File Info:

name: 4936529FEF55F56AF569.mlw
path: /opt/CAPEv2/storage/binaries/314ba89cf0888d305345f94049e3af603aa01593fd0c90be2214246d2dc95c94
crc32: D14D913A
md5: 4936529fef55f56af569eb6d7513a14b
sha1: b8eb2efb44438193fa678c81718bea65778a4eb8
sha256: 314ba89cf0888d305345f94049e3af603aa01593fd0c90be2214246d2dc95c94
sha512: 104e9a6f07bdc686cfb57c94808638d0a3debc5443f3805fade96c129196396fb9bc0801a8daa06ddee34593f0dff198dd1dfb88251ad343896738e3076d5c6f
ssdeep: 24576:vBWelxqsfNMNr79DsIZcGf3ggHFlyyJ4kmCahuGUDRNr+mvQWwTOhmU9zIs3ntz1:8F/Y2jSzUxmlsNeY6e
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BE8523124E2E897FCB6C213C183F0B9F77955E419224B6D7A7C66DE6C28EA56103327C
sha3_384: e1f2b432a456bc2e953163443c8ebe81cfc4b763f173b3863a199b7ffc6d199acdba93163dc993b8272ab4a9e737867f
ep_bytes: 7a59766e70706c5661645848556b7258
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

HackTool:Win32/CobaltStrike!pz also known as:

BkavW32.AIDetectMalware
ClamAVWin.Trojan.Banload-9853585-0
FireEyeGeneric.mg.4936529fef55f56a
SkyhighBehavesLike.Win32.Generic.tm
McAfeeArtemis!4936529FEF55
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
AlibabaHackTool:Win32/CobaltStrike.b1658a22
CrowdStrikewin/malicious_confidence_100% (W)
SymantecPacked.Generic.551
Elasticmalicious (moderate confidence)
CynetMalicious (score: 100)
NANO-AntivirusTrojan.Win32.Miner.jeccbt
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
RisingTrojan.Vindor!8.10CC (RDMK:cmRtazp8s+EWeEFAjF6tX6atT+Az)
DrWebTrojan.PWS.Banker1.30278
SophosTroj/Miner-ABM
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Agent.69WCV8
GoogleDetected
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.994
XcitiumTrojWare.Win32.TrojanDownloader.Banload.RES@8hfp75
MicrosoftHackTool:Win32/CobaltStrike!pz
VaristW32/S-8f4e9221!Eldorado
AhnLab-V3Trojan/Win32.Banload.C3470781
Acronissuspicious
VBA32TrojanPSW.Banker
IkarusTrojan.Win64.CoinMiner
FortinetW32/Banload.BD2A!tr
DeepInstinctMALICIOUS

How to remove HackTool:Win32/CobaltStrike!pz?

HackTool:Win32/CobaltStrike!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment