Crack

HackTool:Win32/CobaltStrike!pz malicious file

Malware Removal

The HackTool:Win32/CobaltStrike!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/CobaltStrike!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine HackTool:Win32/CobaltStrike!pz?


File Info:

name: 9AA052F05B870AAEE5F8.mlw
path: /opt/CAPEv2/storage/binaries/d2d616c43f8072af6daf6eb5bcfe7001faac2733920cd5487dddd96e58b3e400
crc32: EFD3EE8A
md5: 9aa052f05b870aaee5f8f91a79e665ab
sha1: 56e28e27499bc087c8f006fe8d7c8f5717d919bb
sha256: d2d616c43f8072af6daf6eb5bcfe7001faac2733920cd5487dddd96e58b3e400
sha512: 8e991761ae4b4da05cffb8c4fc665d08bbc9977beac8e3652d073931b4520a2dbacfa1761d40ebac2729446dc63e7c64c65dd17f2632f2861284255422e6f868
ssdeep: 12288:wqBF6oVTk26GAE47ROGdO01hPKzQPRic0heA67HaKF8H+Dd1pqSEkdrCb:vBF6727uROGdN1KaC9sHaKF8H0drc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11BE4E084CEAF50F4DA0B6174955FA77F5622270A1F39DCDBC3840D8AD2A7EF11032A66
sha3_384: e9872a9c52acc683d653445bb5d192b627a4b48233c7965faf30270095465105bf97fc367ee46d603221f5f78c4ffdf7
ep_bytes: 504e71696b4a635361724e4a4172484c
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

HackTool:Win32/CobaltStrike!pz also known as:

BkavW32.AIDetectMalware
DrWebTrojan.PWS.Banker1.30278
SkyhighBehavesLike.Win32.Generic.jh
McAfeeGenericRXNR-AT!9AA052F05B87
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
SymantecPacked.Generic.551
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Razy-7332578-0
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
FireEyeGeneric.mg.9aa052f05b870aae
SophosTroj/Miner-ABH
SentinelOneStatic AI – Malicious PE
GoogleDetected
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.965
MicrosoftHackTool:Win32/CobaltStrike!pz
XcitiumTrojWare.Win32.TrojanDownloader.Banload.RES@8hfp75
GDataWin32.Trojan.Agent.6S2VUR
VaristW32/S-8f4e9221!Eldorado
AhnLab-V3Trojan/Win32.Banload.C3470781
Acronissuspicious
VBA32TrojanPSW.Banker
RisingTrojan.Generic@AI.100 (RDML:YEyn92YQi1gqRvnRtgrZvw)
IkarusTrojan.Win64.CoinMiner
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.7267!tr

How to remove HackTool:Win32/CobaltStrike!pz?

HackTool:Win32/CobaltStrike!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment