Crack

HackTool:Win32/CobaltStrike!pz removal guide

Malware Removal

The HackTool:Win32/CobaltStrike!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/CobaltStrike!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine HackTool:Win32/CobaltStrike!pz?


File Info:

name: CB095D48B3D8E6BCBD6E.mlw
path: /opt/CAPEv2/storage/binaries/bcb994a700ba92d9b3ab46e045ba2a36c4dda218036b0e6531d9a5d4faa7f4e5
crc32: EA3F6896
md5: cb095d48b3d8e6bcbd6e093646e701c1
sha1: 745a4bf5bd2a9ac8c7ea2e14049d02618401b1be
sha256: bcb994a700ba92d9b3ab46e045ba2a36c4dda218036b0e6531d9a5d4faa7f4e5
sha512: 92c0c570cb40a003ab6977e406d79ac8d64c86c902e5c7272ee14fc1bf6eb74e376431940d8858df3a0f5b995207775e7807413d3352bae398cd9b7e009f834f
ssdeep: 24576:vBF6727f8UhNnXIhz24GtdepbuqDdHsK+jLsPPfpc:rUUvXjVTo9iKdPi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T111350251DE6B50F8D61B5170212BAB6F96122A050F38ECCBD3C51D87E7ABFF11136826
sha3_384: f3b25664b86149370d2ee29b3a3adf71b96b0594036b3fe334aeef9bc2d96ca4dfdc1599fea9c506a2e133dc3df17f66
ep_bytes: 627755446b486a5a566550484e594248
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

HackTool:Win32/CobaltStrike!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.PWS.Banker1.30278
FireEyeGeneric.mg.cb095d48b3d8e6bc
SkyhighBehavesLike.Win32.Generic.th
McAfeeGenericRXNR-AT!CB095D48B3D8
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaHackTool:Win32/CobaltStrike.c067764e
SymantecPacked.Generic.551
APEXMalicious
ClamAVWin.Trojan.Razy-7331671-0
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
RisingHackTool.CobaltStrike!8.1216E (TFE:3:9ER1rxEHsoO)
SophosTroj/Miner-ABH
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Agent.LW1TU8
GoogleDetected
VaristW32/S-8f4e9221!Eldorado
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.969
XcitiumTrojWare.Win32.TrojanDownloader.Banload.RES@8hfp75
MicrosoftHackTool:Win32/CobaltStrike!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Banload.C3470781
Acronissuspicious
VBA32TrojanPSW.Banker
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R03BH06C124
IkarusTrojan.Win64.CoinMiner
FortinetW32/Agent.7267!tr
DeepInstinctMALICIOUS

How to remove HackTool:Win32/CobaltStrike!pz?

HackTool:Win32/CobaltStrike!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment