Crack

HackTool:Win32/CobaltStrike!pz (file analysis)

Malware Removal

The HackTool:Win32/CobaltStrike!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/CobaltStrike!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine HackTool:Win32/CobaltStrike!pz?


File Info:

name: 5455BD50A057FB2A9522.mlw
path: /opt/CAPEv2/storage/binaries/13bb63a31886cdf544d4cf62826034e715399c325e5d0688b5d4428289ba1a45
crc32: 383917FE
md5: 5455bd50a057fb2a9522f0d5fb46b9d8
sha1: 0a34aef9feaf275b4aa74710d1f6ade3e0abb3ea
sha256: 13bb63a31886cdf544d4cf62826034e715399c325e5d0688b5d4428289ba1a45
sha512: 45858fa98795a18726badebb1339bd1a353bccf1c2034940ea5d7a07288ff49ba4c3ade43b5148139c84d63f9335607cdfeab8ef4cd94fd60521462d969ebe67
ssdeep: 12288:wqBF6oVTk26GXLNaGUnFsnEV+43Ykj7MwunhiFDemTZnNV0XJvMr+DC4:vBF6727XL1+Ki+4ini/T9UDf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E1F4F190DEAF10F5DA1B6530546BAA2F562227091F38ECDBC7C00D8AD76BFF11132969
sha3_384: bbbebe6024d064361088186b23cea3fa2642f8c2623639d8a768f5f3dab69de2e539a7cd3a9e7c0ac13dc6fdf16dc908
ep_bytes: 4c6e45584e67696350694c70724b6465
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

HackTool:Win32/CobaltStrike!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Banker1.30278
ClamAVWin.Trojan.Razy-7332016-0
FireEyeGeneric.mg.5455bd50a057fb2a
SkyhighBehavesLike.Win32.Generic.bh
McAfeeGenericRXNR-AT!5455BD50A057
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaHackTool:Win32/CobaltStrike.5dc6389b
SymantecPacked.Generic.551
APEXMalicious
CynetMalicious (score: 100)
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
SophosTroj/Miner-ABH
IkarusTrojan.Win64.CoinMiner
GDataWin32.Trojan.Agent.U1CCI2
GoogleDetected
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.967
XcitiumTrojWare.Win32.TrojanDownloader.Banload.RES@8hfp75
MicrosoftHackTool:Win32/CobaltStrike!pz
VaristW32/S-8f4e9221!Eldorado
AhnLab-V3Trojan/Win32.Banload.C3470781
Acronissuspicious
VBA32TrojanPSW.Banker
MalwarebytesGeneric.Malware.AI.DDS
RisingTrojan.Generic@AI.100 (RDML:968OpdhQeTYQpNCTYfONNA)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.7267!tr
DeepInstinctMALICIOUS

How to remove HackTool:Win32/CobaltStrike!pz?

HackTool:Win32/CobaltStrike!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment