PUA

PUA.CobaltstrikeRI.S13815542 malicious file

Malware Removal

The PUA.CobaltstrikeRI.S13815542 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.CobaltstrikeRI.S13815542 virus can do?

    Related domains:

    z.whorecord.xyz
    a.tomx.xyz

    How to determine PUA.CobaltstrikeRI.S13815542?

    
    

    File Info:

    crc32: 7DE8DDE9
    md5: 356998e65f2fab768f4851aed5812640
    name: upload_file
    sha1: ad881e08f7fcd4f2b67d087a33d8e092d9515b0b
    sha256: 2fab87f5b4414fe34281a8f8ef042fdec2c8196189d516a82b02bf4a07566553
    sha512: 89e4eaed10edc9ed05d783c6ca676478930c25a7e2230dfbd68951562487b23ce7dcfeb28bfdd653de326c4179871fd3538d145c57a37a5a7bdaef48fa70aadd
    ssdeep: 3072:KlC60GeD6N9Za5Yp6zPC952DmKX0tDV2/jqBkLcP6j5U9k5W:KNxfaWUzPWEKKX0pURLcyjW
    type: MS-DOS executable, MZ for MS-DOS

    Version Info:

    0: [No Data]

    PUA.CobaltstrikeRI.S13815542 also known as:

    ClamAVWin.Trojan.CobaltStrike-8091534-0
    FireEyeGeneric.mg.356998e65f2fab76
    CAT-QuickHealPUA.CobaltstrikeRI.S13815542
    McAfeeCobaltStr-FDWE!356998E65F2F
    CylanceUnsafe
    ZillyaTrojan.Cometer.Win32.949
    SangforMalware
    K7AntiVirusRiskware ( 0050f89b1 )
    BitDefenderGeneric.CBL.Carbanak.3.5F09BBC8
    K7GWRiskware ( 0050f89b1 )
    CrowdStrikewin/malicious_confidence_100% (D)
    Invinceaheuristic
    F-ProtW32/S-2d1b851e!Eldorado
    SymantecML.Attribute.HighConfidence
    APEXMalicious
    AvastWin32:CobaltStrike-A [Trj]
    CynetMalicious (score: 100)
    GDataGeneric.CBL.Carbanak.3.5F09BBC8
    KasperskyHEUR:Trojan.Win32.Cometer.gen
    NANO-AntivirusTrojan.Win32.Inject.fmmnqp
    MicroWorld-eScanGeneric.CBL.Carbanak.3.5F09BBC8
    RisingTrojan.Cometer!8.E150 (TFE:dGZlOgXGthHn7W+TiQ)
    Endgamemalicious (high confidence)
    SophosTroj/Swrort-CH
    F-SecureTrojan.TR/Proxy.Gen
    DrWebBackDoor.Meterpreter.85
    MaxSecureTrojan.Malware.10056239.susgen
    Trapminemalicious.moderate.ml.score
    EmsisoftGeneric.CBL.Carbanak.3.5F09BBC8 (B)
    SentinelOneDFI – Malicious PE
    CyrenW32/S-2d1b851e!Eldorado
    WebrootW32.Malware.Gen
    AviraTR/Proxy.Gen
    MAXmalware (ai score=80)
    Antiy-AVLHackTool/Win32.Inject
    MicrosoftVirTool:Win32/Atosev.A
    ArcabitGeneric.CBL.Carbanak.3.5F09BBC8
    ZoneAlarmHEUR:Trojan.Win32.Cometer.gen
    AhnLab-V3Unwanted/Win32.Agent.R255217
    Acronissuspicious
    VBA32Trojan.Cometer
    ALYacGeneric.CBL.Carbanak.3.5F09BBC8
    Ad-AwareGeneric.CBL.Carbanak.3.5F09BBC8
    MalwarebytesRiskWare.GameHack.CSGO
    PandaTrj/Genetic.gen
    ESET-NOD32a variant of Win32/RiskWare.CobaltStrike.Beacon.A
    TencentMalware.Win32.Gencirc.10b3d535
    YandexTrojan.Atosev!
    IkarusHackTool.CobaltStrike
    eGambitTrojan.Generic
    BitDefenderThetaGen:NN.ZedlaF.34138.mq4@aWOiqYo
    AVGWin32:CobaltStrike-A [Trj]

    How to remove PUA.CobaltstrikeRI.S13815542?

    PUA.CobaltstrikeRI.S13815542 removal tool
    • Download and install GridinSoft Anti-Malware.
    • Open GridinSoft Anti-Malware and perform a “Standard scan“.
    • Move to quarantine” all items.
    • Open “Tools” tab – Press “Reset Browser Settings“.
    • Select proper browser and options – Click “Reset”.
    • Restart your computer.

    About the author

    Paul Valéry

    I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

    Leave a Comment