Backdoor

Backdoor.Win32.Mokes.alvh (file analysis)

Malware Removal

The Backdoor.Win32.Mokes.alvh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Mokes.alvh virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Tswana
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Mokes.alvh?


File Info:

crc32: D8D65D39
md5: eb668f8b9af0ad3417e514f5fe7e95d9
name: EB668F8B9AF0AD3417E514F5FE7E95D9.mlw
sha1: 7ecbf14720d7caeedb3281e32d74e9ed49e943c3
sha256: 5644f15b8381605e559d9bcd22c5c36bb45cba58c53818c165091550d1ba4724
sha512: fb8428446f25a4860360b7d9336ecd237956a049f2a18d5251dd8bd23af40f38d1edcf03920b2929c330c1db22dab0986adcb9c94b436457d683f422ce9f9410
ssdeep: 3072:5KTmxWa6pJGAic3EKJlloF88rlL5spBHYmDNS2xx9:UqxopF3RJToF88JFI7S2
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafull
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x054e

Backdoor.Win32.Mokes.alvh also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen11.57591
MicroWorld-eScanTrojan.GenericKD.45355486
ALYacTrojan.GenericKD.45355486
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.45355486
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.720d7c
BitDefenderThetaGen:NN.ZexaF.34742.omKfaCezqugG
CyrenW32/Trojan.EBFS-5449
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyBackdoor.Win32.Mokes.alvh
AlibabaBackdoor:Win32/Mokes.2fc4894c
Ad-AwareTrojan.GenericKD.45355486
EmsisoftTrojan.GenericKD.45355486 (B)
F-SecureHeuristic.HEUR/AGEN.1140248
SophosMal/Generic-S
AviraHEUR/AGEN.1140248
MicrosoftTrojan:Win32/Glupteba.KMG!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2B411DE
ZoneAlarmBackdoor.Win32.Mokes.alvh
GDataTrojan.GenericKD.45355486
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R362115
Acronissuspicious
MAXmalware (ai score=100)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HIOX
TrendMicro-HouseCallTROJ_GEN.R023C0DA921
RisingTrojan.Kryptik!8.8 (TFE:5:V4nJcY6klTD)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Kryptik.HIFA!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Backdoor.aa7

How to remove Backdoor.Win32.Mokes.alvh?

Backdoor.Win32.Mokes.alvh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment