Crack

HackTool:Win32/CobaltStrike!pz (file analysis)

Malware Removal

The HackTool:Win32/CobaltStrike!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/CobaltStrike!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine HackTool:Win32/CobaltStrike!pz?


File Info:

name: A11D4B47DA2DE85D0E1C.mlw
path: /opt/CAPEv2/storage/binaries/b91534197702bd7a848f60d1486449cf8afbeb8a9d134e63c059e08eba9b1d05
crc32: 9BF8402B
md5: a11d4b47da2de85d0e1c40b50cdf8a05
sha1: 3ffc63413c5dfe4e0f4defded79f9291e6f994f7
sha256: b91534197702bd7a848f60d1486449cf8afbeb8a9d134e63c059e08eba9b1d05
sha512: f9872cc9cbc2a26a396bfc6998f144a180ee32e5404a9fe62ac658d190f2e62de30c5b5230e09cdbbccdb14c7a154a0fa53bfc11b05fc0d5881a7b40b7c65d6a
ssdeep: 12288:wqBF6oVTk26G/YSeoP8wQ1XOXXy7ArpSJELszCFn0n:vBF6727HeoPO+XC7A9GaF0n
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FEC4EF94CEAB54F5E64B6530646FA63FA62122051F38EDCBC3C40E86D767FF1103296A
sha3_384: 6db62ad10f6b0f1169470a3492855c9cf56eee0e1cc56ff2d24cf96f20b5dc6b7d8ce07481b49d84c2000e48c05bef48
ep_bytes: 65544a6541704e59766b4b71414c6569
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

HackTool:Win32/CobaltStrike!pz also known as:

BkavW32.AIDetectMalware
DrWebTrojan.PWS.Banker1.30278
ClamAVWin.Trojan.Coinminer-7332019-0
FireEyeGeneric.mg.a11d4b47da2de85d
SkyhighBehavesLike.Win32.Generic.hh
McAfeeGenericRXNR-AT!A11D4B47DA2D
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
SymantecPacked.Generic.551
CynetMalicious (score: 100)
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
SophosTroj/Miner-ABH
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Agent.S94TQC
GoogleDetected
Antiy-AVLTrojan/Win32.AGeneric
XcitiumTrojWare.Win32.TrojanDownloader.Banload.RES@8hfp75
MicrosoftHackTool:Win32/CobaltStrike!pz
VaristW32/S-8f4e9221!Eldorado
AhnLab-V3Trojan/Win32.Banload.C3470781
Acronissuspicious
VBA32TrojanPSW.Banker
RisingTrojan.Generic@AI.100 (RDML:RnDmknx6+ovmmslNqNIRzQ)
IkarusTrojan.Win64.CoinMiner
FortinetW32/Agent.7267!tr
CrowdStrikewin/malicious_confidence_100% (D)

How to remove HackTool:Win32/CobaltStrike!pz?

HackTool:Win32/CobaltStrike!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment