Crack

Should I remove “HackTool:Win32/CobaltStrike!pz”?

Malware Removal

The HackTool:Win32/CobaltStrike!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/CobaltStrike!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine HackTool:Win32/CobaltStrike!pz?


File Info:

name: BFD380EA0C0105EB6018.mlw
path: /opt/CAPEv2/storage/binaries/a4f52cecd1d59a773c1f857b5b691a4a7d1e3a0ac52707fb8fa7f5824085b10e
crc32: F3AA4DE2
md5: bfd380ea0c0105eb60186003ce6c7a43
sha1: 29e0872024e571764bc03e7050082f6e7d5a3e6a
sha256: a4f52cecd1d59a773c1f857b5b691a4a7d1e3a0ac52707fb8fa7f5824085b10e
sha512: 90c99d62434f5ab32c7740031ffa018bf1b1d65e7ea7602159f82fd4e479c972351b7dfd6cb9f72e67e3ce64b666c6b1f9b94e0fbce1e934714fab2106410f1a
ssdeep: 24576:vBF672l6i2Ncb2ygupgrnACAmZ/NwFC31G3AcMxA7DELKcW7wpebBQLn2IBP3WKm:r56uL3pgrCEdMKPFot
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16E65FAA0EDEF00F4EA035870955BA23F5731270A9B38DDD7C6841E82D677EE2553392A
sha3_384: 63eb24e43b97a952a20360ebf67f3db5fa8e209a5b627d4780f1b5236567f73c51c272a0cbc30add3b3ef8140882e518
ep_bytes: 83ec0c8b44240c8d5c24108944240489
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

HackTool:Win32/CobaltStrike!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Banload.4!c
DrWebTrojan.PWS.Banker1.30278
MicroWorld-eScanTrojan.GenericKD.45989870
FireEyeGeneric.mg.bfd380ea0c0105eb
SkyhighBehavesLike.Win32.Generic.th
McAfeeGenericRXNR-AT!BFD380EA0C01
VIPRETrojan.GenericKD.45989870
SangforTrojan.Win32.Save.a
AlibabaHackTool:Win32/CobaltStrike.0a733cb5
ArcabitTrojan.Generic.D2BDBFEE
SymantecPacked.Generic.551
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ClamAVWin.Malware.Generickdz-9831451-0
BitDefenderTrojan.GenericKD.45989870
NANO-AntivirusTrojan.Win32.Banker1.inibrb
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
EmsisoftTrojan.GenericKD.45989870 (B)
ZillyaDownloader.Banload.Win32.88671
SophosTroj/Miner-ABA
IkarusTrojan.Win64.CoinMiner
JiangminTrojan.Pushel.c
VaristW32/S-8f4e9221!Eldorado
Antiy-AVLTrojan/Win32.AGeneric
XcitiumTrojWare.Win32.TrojanDownloader.Banload.RES@8hfp75
MicrosoftHackTool:Win32/CobaltStrike!pz
GDataTrojan.GenericKD.45989870
GoogleDetected
AhnLab-V3Trojan/Win32.Banload.C3470781
Acronissuspicious
VBA32TrojanPSW.Banker
MAXmalware (ai score=87)
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R002H0CA324
RisingTrojan.Generic@AI.87 (RDMK:tjLZt8jSB20vybEJQ9nBUw)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.7267!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove HackTool:Win32/CobaltStrike!pz?

HackTool:Win32/CobaltStrike!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment