Trojan

TrojanDownloader:Win32/Kuluoz malicious file

Malware Removal

The TrojanDownloader:Win32/Kuluoz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Kuluoz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Behavior consistent with a dropper attempting to download the next stage.
  • Attempts to modify proxy settings

How to determine TrojanDownloader:Win32/Kuluoz?


File Info:

name: F298B9455688F46FCD92.mlw
path: /opt/CAPEv2/storage/binaries/b16f721eeec0e3fc827d3cbebfde1d5520ec82409e5e385af2a0dc97de365485
crc32: 5D210F3E
md5: f298b9455688f46fcd924569e383e1f4
sha1: 47f7ac788772ce59fbf9a92900d263cf46027415
sha256: b16f721eeec0e3fc827d3cbebfde1d5520ec82409e5e385af2a0dc97de365485
sha512: 62ec530bff461784dbc01381eb55324e98a61b2b690e481b3d971a19fa89a571c77a75717f033157e880d1b7f3ec1ed5f6cd26feb66f09c95c29771099f0ff26
ssdeep: 3072:H1j3b64eCVf5YjSYQD0D1Jwat+x+MWmuTiuTKx:H1jr649iSADTt+x+MMTNT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A0049E81E3B09385F87729721A3D0DB01A9EFE6FDB64110A2974FC1C4DB31D36962A97
sha3_384: 714282cef5770bbf6f72376e7e66819fd56a911f3687d5780c31e9b9e67bdc7be59e9db214f74182e686fcd39bde178e
ep_bytes: 558bec83ec7856c745f8000000008d45
timestamp: 2014-03-17 12:41:15

Version Info:

Comments: This installation was built with.
Translation: 0x0000 0x04b0

TrojanDownloader:Win32/Kuluoz also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebBackDoor.Kuluoz.4
MicroWorld-eScanTrojan.Dofoil.Z
FireEyeGeneric.mg.f298b9455688f46f
CAT-QuickHealTrojanPWS.Zbot.Gen
ALYacTrojan.Dofoil.Z
CylanceUnsafe
ZillyaDownloader.Dofoil.Win32.645
SangforSuspicious.Win32.Save.a
K7AntiVirusBackdoor ( 0040f8401 )
K7GWBackdoor ( 0040f8401 )
Cybereasonmalicious.55688f
BitDefenderThetaGen:NN.ZexaF.34294.km0@aeq5ekdi
CyrenW32/Trojan.NIDQ-8042
SymantecPacked.Generic.459
ESET-NOD32Win32/TrojanDownloader.Zortob.B
APEXMalicious
ClamAVWin.Trojan.Zbot-6830587-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Dofoil.Z
NANO-AntivirusTrojan.Win32.Dofoil.cvieqo
SUPERAntiSpywareTrojan.Agent/Gen-Dofoil
AvastWin32:Agent-AZTR [Trj]
TencentMalware.Win32.Gencirc.10b5468b
Ad-AwareTrojan.Dofoil.Z
SophosML/PE-A + Troj/Kuluoz-AQ
ComodoBackdoor.Win32.Androm.DPEI@58bzy6
VIPRETrojan.Win32.Kuluoz.bb (v)
TrendMicroBKDR_KULUOZ.SMJ1
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
EmsisoftTrojan.Dofoil.Z (B)
IkarusTrojan-Spy.Agent
GDataTrojan.Dofoil.Z
JiangminTrojanDownloader.Dofoil.og
Webroot
AviraTR/Spy.Zbot.rhwnflo
MicrosoftTrojanDownloader:Win32/Kuluoz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Dofoil.R101788
Acronissuspicious
McAfeePWS-Zbot-FATG!F298B9455688
MAXmalware (ai score=80)
VBA32TrojanDownloader.Dofoil
MalwarebytesMalware.AI.417904926
TrendMicro-HouseCallBKDR_KULUOZ.SMJ1
RisingMalware.FakeXLS/ICON!1.9C3D (CLASSIC)
YandexTrojan.GenAsa!BXhaFuOloAc
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_75%
FortinetW32/Lockscreen.LOA!tr
AVGWin32:Agent-AZTR [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove TrojanDownloader:Win32/Kuluoz?

TrojanDownloader:Win32/Kuluoz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment