Crack

About “HackTool:Win32/CobaltStrike!pz” infection

Malware Removal

The HackTool:Win32/CobaltStrike!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/CobaltStrike!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine HackTool:Win32/CobaltStrike!pz?


File Info:

name: C4FF7EEE77AD5B3728A3.mlw
path: /opt/CAPEv2/storage/binaries/54e80ae91ede7f15498051102ff2df45f79d75199ef35ad296007a4ab679c00c
crc32: 4377BDE3
md5: c4ff7eee77ad5b3728a3bbe1a3fe2e47
sha1: be41a5536122aaf8fcd1ea6199c4b08e76796af0
sha256: 54e80ae91ede7f15498051102ff2df45f79d75199ef35ad296007a4ab679c00c
sha512: 165538aaf0b4241fa0c639fe8419d642d67da6a49b6832ea4d50e1dabeabdb9e640a18eccfbadb93c0ebe34db4137a638ce71ee7a2f9aa99b1f8b40630af2771
ssdeep: 24576:vBF672l6i2Ncb2ygupgrnACAmZ/NwFC31G3AcMaTH4zxzPEtZHWt+ShCxM:r56uL3pgrCEd2TcF1hCxM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T196556EA0DDEF00F0EA075870955BA23F5625270A9F38DDCBC6841E82E677EF1153396A
sha3_384: 343b16b83c355b02df17632b187e76f3db7e9924db06dffa68de7e2f4046effa80a664d3789076599426056789e495b4
ep_bytes: 83ec0c8b44240c8d5c24108944240489
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

HackTool:Win32/CobaltStrike!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKD.45989870
FireEyeGeneric.mg.c4ff7eee77ad5b37
SkyhighBehavesLike.Win32.Generic.th
McAfeeGenericRXNR-AT!C4FF7EEE77AD
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKD.45989870
SangforTrojan.Win32.Save.a
SymantecPacked.Generic.551
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ClamAVWin.Trojan.Razy-7331670-0
BitDefenderTrojan.GenericKD.45989870
NANO-AntivirusTrojan.Win32.Banker1.inibrb
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
EmsisoftTrojan.GenericKD.45989870 (B)
DrWebTrojan.PWS.Banker1.30278
ZillyaDownloader.Banload.Win32.88671
SophosTroj/Miner-ABH
IkarusTrojan.Win64.CoinMiner
JiangminTrojan.Pushel.c
VaristW32/S-8f4e9221!Eldorado
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.827
MicrosoftHackTool:Win32/CobaltStrike!pz
XcitiumTrojWare.Win32.TrojanDownloader.Banload.RES@8hfp75
ArcabitTrojan.Generic.D2BDBFEE
GDataTrojan.GenericKD.45989870
GoogleDetected
AhnLab-V3Trojan/Win32.Banload.C3470781
Acronissuspicious
ALYacTrojan.GenericKD.45989870
MAXmalware (ai score=82)
VBA32TrojanPSW.Banker
TrendMicro-HouseCallTROJ_GEN.R03BH0CC224
RisingTrojan.Generic@AI.100 (RDML:1z7aVdU3R5K15Cx0S+8jiw)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.7267!tr
CrowdStrikewin/malicious_confidence_100% (W)

How to remove HackTool:Win32/CobaltStrike!pz?

HackTool:Win32/CobaltStrike!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment