Crack

HackTool:Win32/CobaltStrike!pz malicious file

Malware Removal

The HackTool:Win32/CobaltStrike!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/CobaltStrike!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine HackTool:Win32/CobaltStrike!pz?


File Info:

name: 84484E941DC1D0DCDBB4.mlw
path: /opt/CAPEv2/storage/binaries/3c323891c5cd54f2a4eed1e548d454edc84af3a59d8318bbd8458ea77dda0f88
crc32: 0D1B7004
md5: 84484e941dc1d0dcdbb43062dd207075
sha1: e9fc20e548ac9723cbdefa5f93ca42b3276130fb
sha256: 3c323891c5cd54f2a4eed1e548d454edc84af3a59d8318bbd8458ea77dda0f88
sha512: 73f1ecde448689c2c7dfd504133a0e10694b47aee4da1bdac8e2e82388cbbf1aaca745c57370eb0f4fc965eeda08ce74810c0b9471b4a854897712dedeae1dcc
ssdeep: 12288:wqBF6oVTk26Gpx7GfzWd/sAnxvWbNBUEgPZyR6FNrcszDE32KFOAoAiv0lKBSrYP:vBF6727z9fxvWbwv0R6FNp62Gl5cJrpj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A3050155DEAB50F4D60B6130946B973F591227050F38EDDBC3D80E8AD3ABEF2103696A
sha3_384: 815d6b421020cfafde8bfde07c5cbb1fc6982741be477f97707310acfd84ebad8f08414c90d9b36219af5cd914b4b1a7
ep_bytes: 52424f6145686a43485156724e487a72
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

HackTool:Win32/CobaltStrike!pz also known as:

BkavW32.AIDetectMalware
ClamAVWin.Malware.Generic-10018700-0
FireEyeGeneric.mg.84484e941dc1d0dc
SkyhighBehavesLike.Win32.Generic.bh
McAfeeGenericRXNR-AT!84484E941DC1
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
SymantecPacked.Generic.551
APEXMalicious
CynetMalicious (score: 100)
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
DrWebTrojan.PWS.Banker1.30278
SophosTroj/Miner-ABH
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Agent.37FGRP
GoogleDetected
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.963
XcitiumTrojWare.Win32.TrojanDownloader.Banload.RES@8hfp75
MicrosoftHackTool:Win32/CobaltStrike!pz
VaristW32/S-8f4e9221!Eldorado
AhnLab-V3Trojan/Win32.Banload.C3470781
Acronissuspicious
VBA32TrojanPSW.Banker
RisingTrojan.Generic@AI.100 (RDML:xZQkwyVvwZUxTaNBTZn+oA)
IkarusTrojan.Win64.CoinMiner
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.7267!tr
CrowdStrikewin/malicious_confidence_100% (D)

How to remove HackTool:Win32/CobaltStrike!pz?

HackTool:Win32/CobaltStrike!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment