Crack

HackTool:Win32/CobaltStrike!pz removal guide

Malware Removal

The HackTool:Win32/CobaltStrike!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/CobaltStrike!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine HackTool:Win32/CobaltStrike!pz?


File Info:

name: C514FBF87BDC4DAACE70.mlw
path: /opt/CAPEv2/storage/binaries/762633f5ea597e316564ca2bbf4e8633f879c7922fef97ff6f0aa3b938d02e8a
crc32: 5E02E03C
md5: c514fbf87bdc4daace704d001785f59a
sha1: 2458de371d7807316963e27a3337182ee70b88ae
sha256: 762633f5ea597e316564ca2bbf4e8633f879c7922fef97ff6f0aa3b938d02e8a
sha512: fedfbbda0b02846e7eb9bac66516c2575243ebe5bd482bf4f67e2dbae688c1b4b4a633ae2f919c7ad95a68782ac032db282bf80c3ef008068247e71f1a167d9d
ssdeep: 24576:vBF672l6i2Ncb2ygupgrnACAmZ/NwFC31G3AcMaMYXoGQqEOeXhhH:r56uL3pgrCEd2hXcrH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14E556DA0DDEF10F0EA079870955BA23F5225270A9F38DDCBC6841E82D677EF1153396A
sha3_384: fdd4cf5e8ce17033462e804a08c6e7c5f0764c1e86b97439ca3705c8ea6fd1634fa16c19dd71114fd16a2f846e578094
ep_bytes: 83ec0c8b44240c8d5c24108944240489
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

HackTool:Win32/CobaltStrike!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Banker1.30278
MicroWorld-eScanTrojan.GenericKD.45989870
SkyhighBehavesLike.Win32.Generic.th
McAfeeGenericRXNR-AT!C514FBF87BDC
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.Banload.Win32.88671
SangforTrojan.Win32.Save.a
SymantecPacked.Generic.551
ClamAVWin.Trojan.Razy-7332604-0
BitDefenderTrojan.GenericKD.45989870
NANO-AntivirusTrojan.Win32.Banker1.inibrb
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
EmsisoftTrojan.GenericKD.45989870 (B)
GoogleDetected
VIPRETrojan.GenericKD.45989870
FireEyeGeneric.mg.c514fbf87bdc4daa
SophosTroj/Miner-ABH
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.45989870
JiangminTrojan.Pushel.c
VaristW32/S-8f4e9221!Eldorado
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.819
XcitiumTrojWare.Win32.TrojanDownloader.Banload.RES@8hfp75
ArcabitTrojan.Generic.D2BDBFEE
MicrosoftHackTool:Win32/CobaltStrike!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Banload.C3470781
Acronissuspicious
ALYacTrojan.GenericKD.45989870
VBA32TrojanPSW.Banker
TrendMicro-HouseCallTROJ_GEN.R03BH0CBP24
RisingTrojan.Generic@AI.100 (RDML:1z7aVdU3R5K15Cx0S+8jiw)
IkarusTrojan.Win64.CoinMiner
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.7267!tr
CrowdStrikewin/malicious_confidence_100% (D)

How to remove HackTool:Win32/CobaltStrike!pz?

HackTool:Win32/CobaltStrike!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment