Backdoor

Backdoor:Win32/Kelihos!pz (file analysis)

Malware Removal

The Backdoor:Win32/Kelihos!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Kelihos!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Attempts to access Bitcoin/ALTCoin wallets
  • Touches a file containing cookies, possibly for information gathering
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Kelihos!pz?


File Info:

name: 8D5DB354EB48BDFEB624.mlw
path: /opt/CAPEv2/storage/binaries/7efd885f60c6a25fd1890d80a5bc0e012243ad9610f69e1c277fe8ce349345cc
crc32: 90923773
md5: 8d5db354eb48bdfeb624c12d9a0a1190
sha1: d1e3d188545a7da98d663096ec7c5453843ef75a
sha256: 7efd885f60c6a25fd1890d80a5bc0e012243ad9610f69e1c277fe8ce349345cc
sha512: 784e5b84c10ff74604eac19fce822f40d47f913aa2bc2749f914aa36100ddd715b48f425ed0dadea3de2150fc173e0ec660ecd0f20e4fed7ec72036c77472cdf
ssdeep: 12288:iyrOQCTepqK5JbQtZWhQx2tb7Pbwv2ndejXxQMcKZcNZVlFslMchF41pj/+/ALAJ:bgTOXstZIP9Ccdejx5ZcR9chFR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1820523429AB64CDCD846C83EB225E88341519F1EFBB8D76E600E54FAB49F4B30715EE1
sha3_384: eb042acb47fcf7d1131073772e997db7a1c6fe8b28cd27e796c67520958d5ea9b687ffbb8e4ca26f29712232aec47cc0
ep_bytes: 66ba00ff8bcc663bca726bb96b324000
timestamp: 2001-01-03 18:51:33

Version Info:

0: [No Data]

Backdoor:Win32/Kelihos!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lKKk
ElasticWindows.Generic.Threat
MicroWorld-eScanTrojan.VIZ.Gen.1
SkyhighBehavesLike.Win32.Shohdi.cc
McAfeeGeneric-FANP!8D5DB354EB48
MalwarebytesMalware.Heuristic.3005
ZillyaBackdoor.Hlux.Win32.10006
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f72a1 )
AlibabaBackdoor:Win32/Obfuscator.fc2ce601
K7GWTrojan ( 0040f72a1 )
Cybereasonmalicious.4eb48b
BitDefenderThetaGen:NN.ZexaF.36802.YmX@aqeK9Iai
VirITTrojan.Win32.Crypt_s.GRA
SymantecTrojan.FakeAV
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.BWCH
APEXMalicious
TrendMicro-HouseCallBKDR_HLUX.SMP
ClamAVWin.Trojan.Agent-1241463
KasperskyBackdoor.Win32.Hlux.cri
BitDefenderTrojan.VIZ.Gen.1
NANO-AntivirusTrojan.Win32.Hlux.dwdgdm
AvastWin32:Evo-gen [Trj]
TencentBackdoor.Win32.Hlux.cri
EmsisoftTrojan.VIZ.Gen.1 (B)
F-SecureTrojan.TR/Kryptik.oenzp
DrWebBackDoor.Slym.12859
VIPRETrojan.VIZ.Gen.1
TrendMicroBKDR_HLUX.SMP
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.8d5db354eb48bdfe
SophosMal/Generic-S
IkarusTrojan.Crypt
JiangminBackdoor/Hlux.esm
WebrootTrojan.Gen
GoogleDetected
AviraTR/Kryptik.oenzp
VaristW32/FakeAlert.ACF.gen!Eldorado
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Kelihos!pz
XcitiumBackdoor.Win32.Hlux.DUHE@5a7ra1
ArcabitTrojan.VIZ.Gen.1
ZoneAlarmBackdoor.Win32.Hlux.cri
GDataTrojan.VIZ.Gen.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R107095
VBA32Trojan.FakeAV.01657
ALYacTrojan.VIZ.Gen.1
MAXmalware (ai score=100)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Hlux!8.159 (TFE:1:s8281T3KaSE)
YandexBackdoor.Hlux!/Wd/jGxRefg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.BD!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudBackdoor:Win/Hlux.cri

How to remove Backdoor:Win32/Kelihos!pz?

Backdoor:Win32/Kelihos!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment