Crack

What is “HackTool:Win32/CobaltStrike!pz”?

Malware Removal

The HackTool:Win32/CobaltStrike!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/CobaltStrike!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine HackTool:Win32/CobaltStrike!pz?


File Info:

name: 84DDBCACF1B39EF13FA1.mlw
path: /opt/CAPEv2/storage/binaries/397dad7b1ee96a50b040d9775616f954c9c887be245b019cde369f0f934d6005
crc32: B8D10D8C
md5: 84ddbcacf1b39ef13fa15e5501680997
sha1: d5aac1269031e970b76f26343af17ccd118f3ac0
sha256: 397dad7b1ee96a50b040d9775616f954c9c887be245b019cde369f0f934d6005
sha512: dbf933f89d6d4197095b7bf3175f743c1bcba83a56454873ad692d2783e4428c712f5d5aeebf8ec3391949b5aedc85072ecd7e5b809282cc1712a74d75a743fc
ssdeep: 12288:wqBF6oVTk26GXg47pimukTkToYsMmuawqMO:vBF6727Xx7sRgkT1sMFav
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16694CF94DEBB50F4E60B9430956FA63FA62223091F38EDDBC3C40D86D766EF11432966
sha3_384: 43de3e19bd756b7779c82edb441ffea6017de39d07280b4edac7877adbee8af9be542f4fd556e9d597ea18a45bd4b497
ep_bytes: 5a625576455a67547364445845685959
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

HackTool:Win32/CobaltStrike!pz also known as:

BkavW32.AIDetectMalware
DrWebTrojan.PWS.Banker1.30278
FireEyeGeneric.mg.84ddbcacf1b39ef1
SkyhighBehavesLike.Win32.Generic.gh
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
SymantecPacked.Generic.551
CynetMalicious (score: 100)
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
SophosTroj/Miner-ABH
SentinelOneStatic AI – Malicious PE
GoogleDetected
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.923
XcitiumTrojWare.Win32.TrojanDownloader.Banload.RES@8hfp75
MicrosoftHackTool:Win32/CobaltStrike!pz
GDataWin32.Trojan.Agent.K6H2Q1
VaristW32/S-8f4e9221!Eldorado
AhnLab-V3Trojan/Win32.Banload.C3470781
Acronissuspicious
McAfeeGenericRXNR-AT!84DDBCACF1B3
VBA32TrojanPSW.Banker
RisingTrojan.Generic@AI.100 (RDML:rT9vDMGbZii2viOR7NDEmg)
IkarusTrojan.Win64.CoinMiner
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.7267!tr

How to remove HackTool:Win32/CobaltStrike!pz?

HackTool:Win32/CobaltStrike!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment