Backdoor

Backdoor:Win32/Koceg!pz (file analysis)

Malware Removal

The Backdoor:Win32/Koceg!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Koceg!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Backdoor:Win32/Koceg!pz?


File Info:

name: E9732199980C6BA86043.mlw
path: /opt/CAPEv2/storage/binaries/93e9ed49c2f0eeeac0966b238e5017123fbbe65815e22ca1ca8b332787808779
crc32: 24AA3864
md5: e9732199980c6ba860432846c5285c07
sha1: 8c9a6b346539f9d831032b96f2a340c9dbd1f8b7
sha256: 93e9ed49c2f0eeeac0966b238e5017123fbbe65815e22ca1ca8b332787808779
sha512: 74f5284ebd3814a4573c4e178247f9928e903d2d6bac43836a6cf4881356211cd54f4a175a2745d668d03ee80ecd70432f341162358724de7b63e28ca9cfaba1
ssdeep: 384:0VYix/52wnu7AxZSLU5HxyGzF4lfY0uBQey2MFF30M7hQ19WcK:0VH/52w2AyUtxJYfYuFFkgh+W
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10F532A59EB42EC77C1ED04F65B54885ABFBEFE7006A85717CB00274D28F29D7A824389
sha3_384: f2ea4aba72ef390064a98d3ec898a4d6939a6c000ef566e960027f12628008082221421f4da46be50c3924aee34512dd
ep_bytes: 00000000000000000000000000000000
timestamp: 2008-04-19 08:02:16

Version Info:

0: [No Data]

Backdoor:Win32/Koceg!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Socks.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKDZ.70943
FireEyeGeneric.mg.e9732199980c6ba8
McAfeeArtemis!E9732199980C
MalwarebytesSock.Backdoor.Bot.DDS
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004bcce41 )
AlibabaBackdoor:Win32/Koceg.4f9b73cb
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.46539f
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 100)
APEXMalicious
BitDefenderTrojan.GenericKDZ.70943
AvastWin32:Socks-AC [Wrm]
SophosMal/Generic-S
BaiduWin32.Backdoor.IRCBot.a
F-SecureWorm.WORM/Socks.ex
VIPRETrojan.GenericKDZ.70943
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.70943 (B)
SentinelOneStatic AI – Malicious PE
VaristW32/Backdoor.J.gen!Eldorado
AviraWORM/Socks.ex
Antiy-AVLTrojan[Backdoor]/Win32.Koceg
Kingsoftmalware.kb.b.997
MicrosoftBackdoor:Win32/Koceg!pz
ArcabitTrojan.Generic.D1151F
GDataTrojan.GenericKDZ.70943
GoogleDetected
Acronissuspicious
ALYacTrojan.GenericKDZ.70943
MAXmalware (ai score=89)
Cylanceunsafe
PandaTrj/CI.A
RisingWorm.Socks!1.A966 (CLASSIC)
IkarusBackdoor.Win32.Koceg
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenericKDZ.70943!dam
AVGWin32:Socks-AC [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Koceg!pz?

Backdoor:Win32/Koceg!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment