Crack

HackTool:Win32/CobaltStrike!pz (file analysis)

Malware Removal

The HackTool:Win32/CobaltStrike!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/CobaltStrike!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine HackTool:Win32/CobaltStrike!pz?


File Info:

name: 32F2881616F098C843E3.mlw
path: /opt/CAPEv2/storage/binaries/fcd3925663c4e61710ad35ca1d8a6da506ef2108c5602775eb4cefb99e92a001
crc32: B0E7ACB6
md5: 32f2881616f098c843e3056b90caa662
sha1: 18641ad5e40e6b064e65c706f2df66df8766a4b0
sha256: fcd3925663c4e61710ad35ca1d8a6da506ef2108c5602775eb4cefb99e92a001
sha512: b296774a2584d92ddfc0d2dda85a1756c67e0b49c5fa20161d3a33554756c8e95e4e6cbc90b7d66185761d16bf03fde34e79b5837a2e803da7befe41074e4fa7
ssdeep: 24576:vBWelxqsfNMNr79DsIZcGf3ggHFlyyJ4kmCahuGUDRNr+u4LMxNI1xr6fmoA:8F/Y2jSzU0TlB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B16523019E1E4DBECB1D1278187F1B8F63915E40A320A5D7EAC76AD1C15EADB24339BC
sha3_384: 4506e7c571503f1b223204f4c9e647930dab7dade56c545e5399d4bf8d5e3e9eb1e1c08de43e4e30adf0de67cd531616
ep_bytes: 7a59766e70706c5661645848556b7258
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

HackTool:Win32/CobaltStrike!pz also known as:

BkavW32.AIDetectMalware
CyrenCloudW32/S-8f4e9221!Eldorado
LionicTrojan.Win32.Banload.4!c
Elasticmalicious (moderate confidence)
DrWebTrojan.PWS.Banker1.30278
FireEyeGeneric.mg.32f2881616f098c8
SkyhighBehavesLike.Win32.Generic.tm
SangforSuspicious.Win32.Save.a
AlibabaHackTool:Win32/CobaltStrike.b1658a22
CrowdStrikewin/malicious_confidence_100% (W)
SymantecPacked.Generic.551
CynetMalicious (score: 100)
NANO-AntivirusTrojan.Win32.Miner.jeccbt
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
SophosTroj/Miner-ABM
IkarusTrojan.Win64.CoinMiner
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftHackTool:Win32/CobaltStrike!pz
XcitiumTrojWare.Win32.TrojanDownloader.Banload.RES@8hfp75
GDataWin32.Trojan.Agent.AXIZQV
VaristW32/S-8f4e9221!Eldorado
AhnLab-V3Trojan/Win32.Banload.C3470781
Acronissuspicious
McAfeeArtemis!32F2881616F0
MalwarebytesGeneric.Malware.AI.DDS
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Banload.BD2A!tr
DeepInstinctMALICIOUS

How to remove HackTool:Win32/CobaltStrike!pz?

HackTool:Win32/CobaltStrike!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment