Crack

What is “HackTool:Win32/CobaltStrike!pz”?

Malware Removal

The HackTool:Win32/CobaltStrike!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/CobaltStrike!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine HackTool:Win32/CobaltStrike!pz?


File Info:

name: BF3D1A0637FB0DAB9E0B.mlw
path: /opt/CAPEv2/storage/binaries/64e70d6aadbf22fd3bd1db16019972ffecdd46210bb6adc30038b4aa7e43df8d
crc32: B24BB2AC
md5: bf3d1a0637fb0dab9e0b99a1f1fa3753
sha1: 67b701b19ad8a472e39179a627d87e333ddf85d2
sha256: 64e70d6aadbf22fd3bd1db16019972ffecdd46210bb6adc30038b4aa7e43df8d
sha512: 2b5e310742b9810c72d2f71ba0d2e7f47827088edd2b741edffae72da920e0c62ac2970a620ee6e116e65d1219908b9bd5bf2e53cf7e9e8d06a8a24366275aa4
ssdeep: 24576:vBWelxqsfNMNr79DsIZcGf7hao4IvaOwJXXZpVK:8F/DE7OwHK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1351523465E7F493ECA0C26385C3F0B4F5B815A49031DF5D7DBCA6EA8CA4DA9B14322B4
sha3_384: 86ca56534b65b33c82fa40943a2711494562f32eb2d93b976d912ba26ee9222f02e1e700c55c91a07de78eacdbabdf55
ep_bytes: 7a59766e70706c5661645848556b7258
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

HackTool:Win32/CobaltStrike!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Banload.4!c
MicroWorld-eScanGen:Variant.Ulise.267041
SkyhighBehavesLike.Win32.Generic.cm
ALYacGen:Variant.Ulise.267041
SangforSuspicious.Win32.Save.a
AlibabaHackTool:Win32/CobaltStrike.cec5862c
CrowdStrikewin/malicious_confidence_100% (D)
SymantecPacked.Generic.551
CynetMalicious (score: 100)
ClamAVWin.Trojan.Banload-9853585-0
BitDefenderGen:Variant.Ulise.267041
NANO-AntivirusTrojan.Win32.Miner.jeccbt
EmsisoftGen:Variant.Ulise.267041 (B)
DrWebTrojan.PWS.Banker1.30278
VIPREGen:Variant.Ulise.267041
SophosTroj/Miner-ABM
IkarusTrojan.Win64.CoinMiner
GDataGen:Variant.Ulise.267041
VaristW32/S-8f4e9221!Eldorado
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.993
XcitiumTrojWare.Win32.TrojanDownloader.Banload.RES@8hfp75
ArcabitTrojan.Ulise.D41321
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
MicrosoftHackTool:Win32/CobaltStrike!pz
GoogleDetected
AhnLab-V3Trojan/Win32.Banload.C3470781
Acronissuspicious
McAfeeArtemis!BF3D1A0637FB
VBA32TrojanPSW.Banker
MalwarebytesGeneric.Malware.AI.DDS
RisingTrojan.Generic@AI.100 (RDML:kug11jYqpTxRxwIt53NQCw)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Banload.BD2A!tr
DeepInstinctMALICIOUS

How to remove HackTool:Win32/CobaltStrike!pz?

HackTool:Win32/CobaltStrike!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment