Crack

HackTool:Win32/CobaltStrike!pz information

Malware Removal

The HackTool:Win32/CobaltStrike!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/CobaltStrike!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine HackTool:Win32/CobaltStrike!pz?


File Info:

name: 17B4C41754384C435E86.mlw
path: /opt/CAPEv2/storage/binaries/cfd77ed349fd706a844596fb6a465cc32b0c235f9df9ca3d665fe3b2b6ac4541
crc32: 19C0281B
md5: 17b4c41754384c435e868a429405a597
sha1: 9c10e42de1c3ea61496da864e3adc73a0653b2ed
sha256: cfd77ed349fd706a844596fb6a465cc32b0c235f9df9ca3d665fe3b2b6ac4541
sha512: 553916e1349cdae8242175b8020cf9df5e4ef21d08fbbc0f9791302a53f70fbc24e09dc5d9f3b11318bc07e02cac26ee3030404304a5a1eb769ec16294cba983
ssdeep: 24576:vBF6727HeoPO+XC7A9GaFu3PzZtvIaUniops0a3SmSQ:rOYkZtg90vV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12B150145CEAB14F5D60B6034686FA67FAA2126051F38EEDBC3C40D8AD75BFF11032969
sha3_384: 3ade4676cbd7ba2b0039237d0854c2097ccb53dbbf2f9c353cd4bb6ead37102e2b5d5151583d4793965d73a5d2bf8bd0
ep_bytes: 65544a6541704e59766b4b71414c6569
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

HackTool:Win32/CobaltStrike!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (moderate confidence)
ClamAVWin.Trojan.Coinminer-7332019-0
FireEyeGeneric.mg.17b4c41754384c43
SkyhighBehavesLike.Win32.Generic.dh
McAfeeGenericRXNR-AT!17B4C4175438
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaHackTool:Win32/CobaltStrike.b1c58fc7
SymantecPacked.Generic.551
APEXMalicious
CynetMalicious (score: 100)
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
SophosTroj/Miner-ABH
DrWebTrojan.PWS.Banker1.30278
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Agent.27WVM7
GoogleDetected
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.963
XcitiumTrojWare.Win32.TrojanDownloader.Banload.RES@8hfp75
MicrosoftHackTool:Win32/CobaltStrike!pz
VaristW32/S-8f4e9221!Eldorado
AhnLab-V3Trojan/Win32.Banload.C3470781
Acronissuspicious
VBA32TrojanPSW.Banker
MalwarebytesGeneric.Malware.AI.DDS
RisingTrojan.Generic@AI.100 (RDML:t0cYP/Ew39vH9M1xzv0wQg)
IkarusTrojan.Win64.CoinMiner
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.7267!tr
DeepInstinctMALICIOUS

How to remove HackTool:Win32/CobaltStrike!pz?

HackTool:Win32/CobaltStrike!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment