Crack

How to remove “HackTool:Win32/CobaltStrike!pz”?

Malware Removal

The HackTool:Win32/CobaltStrike!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/CobaltStrike!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine HackTool:Win32/CobaltStrike!pz?


File Info:

name: 92E78C29948DAEA8E5D8.mlw
path: /opt/CAPEv2/storage/binaries/91e7de7c1f442c77521be56dd69d8aaf184c2ed678238f9713fdd687cff7f415
crc32: EB87017F
md5: 92e78c29948daea8e5d82c3eda02670c
sha1: e70a244cf0a421e15e8c0b11ba57566de8744cbf
sha256: 91e7de7c1f442c77521be56dd69d8aaf184c2ed678238f9713fdd687cff7f415
sha512: cce48fc2b04447e23dcdc390a08ac9bac75099c7c2b8d7d3898c8065e91f294c12bd3d2d30d899fb2a6ab584ee4fa4d095d8b777ef391cf631440e5de58ddc15
ssdeep: 24576:vBWelxqsfNMNr79DsI/AZOqXyepGbs+WQNqTsPMOne7oO:8F/A1BOdP4oO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19F452302AF6E857ACF5D1279146F0B8F62E04A054326B4D7F7D4AEEBC94BCD8112366C
sha3_384: 31726be7569ce54afca468282fdd58cf7781e684f8120c75912956eebd64a6d65f78cb2ba602e57c8d411435a80f5975
ep_bytes: 7a59766e70706c5661645848556b7258
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

HackTool:Win32/CobaltStrike!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Banload.4!c
FireEyeGeneric.mg.92e78c29948daea8
SkyhighBehavesLike.Win32.Generic.tm
SangforSuspicious.Win32.Save.a
AlibabaHackTool:Win32/CobaltStrike.b1658a22
SymantecPacked.Generic.551
Elasticmalicious (moderate confidence)
CynetMalicious (score: 100)
ClamAVWin.Trojan.Banload-9853585-0
NANO-AntivirusTrojan.Win32.Miner.jeccbt
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
DrWebTrojan.PWS.Banker1.30278
SophosTroj/Miner-ABM
IkarusTrojan.Win64.CoinMiner
VaristW32/S-8f4e9221!Eldorado
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.995
XcitiumTrojWare.Win32.TrojanDownloader.Banload.RES@8hfp75
MicrosoftHackTool:Win32/CobaltStrike!pz
GDataWin32.Trojan.Agent.3PQ4E3
GoogleDetected
AhnLab-V3Trojan/Win32.Banload.C3470781
Acronissuspicious
McAfeeArtemis!92E78C29948D
VBA32TrojanPSW.Banker
MalwarebytesGeneric.Malware.AI.DDS
RisingTrojan.Vindor!8.10CC (RDMK:cmRtazp8s+EWeEFAjF6tX6atT+Az)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Banload.BD2A!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove HackTool:Win32/CobaltStrike!pz?

HackTool:Win32/CobaltStrike!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment