Malware

Mal/Koceg-A malicious file

Malware Removal

The Mal/Koceg-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Koceg-A virus can do?

  • Sample contains Overlay data
  • HTTPS urls from behavior.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Mal/Koceg-A?


File Info:

name: 3A5A7C6CFCF48FAB0FB3.mlw
path: /opt/CAPEv2/storage/binaries/f7fa7d3121cca11238a3339386ce33ac1c981a9d6c19d6e558a0948fc5751b99
crc32: 3AB3D4ED
md5: 3a5a7c6cfcf48fab0fb3ad6a47538637
sha1: 17e8aeb2263226e289236427b2cc068f52691832
sha256: f7fa7d3121cca11238a3339386ce33ac1c981a9d6c19d6e558a0948fc5751b99
sha512: cbf59f06202fc5ff6d3e88847c55776b04c87384c6ac994dc7477824c86d8b657da902a49ee91c697bff8ec65f804dd8e8429476381b62ab9e7be564f8f76839
ssdeep: 6144:B5Gyw53bS9P1JbSankP+6bCy5bSxbS/EnkP+6b0Eu+YnkP+6bu3heDFnkP+6bDRo:3W5rMPzQ+byFeQ+XEJf+RRp+62
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F474126B73CB9727F6023CFBD7FE54A0087B12909DC6A4B0E69AB3F75465D418085B88
sha3_384: 1927238cb47f455c6e75952600bea30220f84eb8b5dd2e7e96f2f8817fd70a7a15e18fb876032811fafc30ea34d280ff
ep_bytes: 60be000041008dbe0010ffff5783cdff
timestamp: 2008-03-20 15:37:19

Version Info:

0: [No Data]

Mal/Koceg-A also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.Crypt.AI
ClamAVWin.Worm.Socks-7102088-0
CAT-QuickHealWorm.Socks.S.mue
ALYacTrojan.Crypt.AI
MalwarebytesSmall.Trojan.Downloader.DDS
ZillyaDownloader.Small.Win32.20275
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004ac0a31 )
K7GWTrojan ( 004ac0a31 )
Cybereasonmalicious.cfcf48
BaiduWin32.Trojan-Downloader.Agent.au
VirITTrojan.Win32.Generic.CNP
CyrenW32/Downloader.OKAP-4554
SymantecW32.SillyFDC
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Socks.NAL
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Crypt.AI
NANO-AntivirusTrojan.Win32.Small.cukqoa
AvastWin32:Injecter-AT [Trj]
TencentMalware.Win32.Gencirc.10beb1f8
Ad-AwareTrojan.Crypt.AI
EmsisoftTrojan.Crypt.AI (B)
F-SecureTrojan.TR/Dldr.Agent.agl
DrWebTrojan.Click.18149
VIPRETrojan.Crypt.AI
TrendMicroWORM_SOCKS.BL
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.3a5a7c6cfcf48fab
SophosMal/Koceg-A
IkarusTrojan-Downloader.Win32.Small
GDataWin32.Trojan.PSE.1VIBKD6
JiangminTrojanDownloader.Small.bkwm
AviraTR/Dldr.Agent.agl
MAXmalware (ai score=87)
Antiy-AVLTrojan[Downloader]/Win32.Small
XcitiumTrojWare.Win32.TrojanDownloader.Small.CA@1a4bmh
ArcabitTrojan.Crypt.AI
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Worm/Win32.Socks.R36675
McAfeeGenericRXAA-AA!3A5A7C6CFCF4
VBA32SScope.Worm.Socks.afv
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_SOCKS.BL
RisingWorm.Autorun!8.50 (TFE:5:NHxeOwuKuTV)
YandexTrojan.GenAsa!O3RxkwH4flU
SentinelOneStatic AI – Malicious PE
FortinetW32/Socks.NAK!tr
BitDefenderThetaAI:Packer.88108EE31B
AVGWin32:Injecter-AT [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Mal/Koceg-A?

Mal/Koceg-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment