Backdoor

About “Backdoor.Dcrat” infection

Malware Removal

The Backdoor.Dcrat is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Dcrat virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • A script process created a new process
  • Attempts to interact with an Alternate Data Stream (ADS)

How to determine Backdoor.Dcrat?


File Info:

name: 221359EC07A77F92800A.mlw
path: /opt/CAPEv2/storage/binaries/b7367c89606c6d554a3ff84ca6bb8948de0b64e11dc263c0ad7125f8391e2d91
crc32: 4AE0F17C
md5: 221359ec07a77f92800a1cbf974de91a
sha1: 080857c9889b80f6378964800132605b3ce0a8a9
sha256: b7367c89606c6d554a3ff84ca6bb8948de0b64e11dc263c0ad7125f8391e2d91
sha512: 88a06b273e20e76e78b78df241e76e4ad3cff1fc86a9e2b5e78fa050436322a60656ee13fc044aba21bd1b1db0312ebc4890449386648b2b4adc29389b429dcd
ssdeep: 49152:UbA304iQMzxdb/RJ68SdcVveWxuU+Gy5LR2Og0r+/UBkqH5:UbMiQMz/S1K2WxcGMsqrpbZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ABD5DF023E40CA12F4181633C6FF452847B4AD556BA6E71B7EBA376D55223A37C0DACB
sha3_384: 732fe7a896700218182caf1cf4ee9fa55031bf894700c8b4e18b98ce5ae2e36a77398c598bd22d208e43c59e13bc2a90
ep_bytes: e874040000e988feffff3b0d68e64300
timestamp: 2020-12-01 18:00:55

Version Info:

0: [No Data]

Backdoor.Dcrat also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Makop.trQA
MicroWorld-eScanTrojan.GenericKD.61022071
CAT-QuickHealBackdoor.Dcrat
McAfeeArtemis!221359EC07A7
CylanceUnsafe
VIPRETrojan.GenericKD.61022071
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 0058ebd51 )
AlibabaBackdoor:MSIL/DCRat.864373e0
K7GWSpyware ( 0058ebd51 )
Cybereasonmalicious.c07a77
CyrenW32/MSIL_Agent.LQ.gen!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Uztuby-9855059-0
KasperskyUDS:Trojan-Spy.MSIL.Stealer.gen
BitDefenderTrojan.GenericKD.61022071
NANO-AntivirusTrojan.Win32.Stealer.jpvmhp
AvastWin32:RATX-gen [Trj]
TencentWin32.Backdoor.Agent.Hnax
Ad-AwareTrojan.GenericKD.61022071
SophosMal/RarMal-R
ComodoMalware@#iys4yp6dt8oo
DrWebTrojan.PWS.StealerNET.124
TrendMicroTROJ_GEN.R03BC0PG522
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeTrojan.GenericKD.61022071
EmsisoftTrojan.GenericKD.61022071 (B)
SentinelOneStatic AI – Malicious SFX
GDataWin32.Trojan.BSE.1CL7UZW
AviraVBS/Runner.VPG
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.3CE9
MicrosoftTrojan:Win32/Skeeyah.A!rfn
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.34806.zs0@aaZ2SZli
ALYacTrojan.GenericKD.61022071
MalwarebytesSpyware.PasswordStealer
TrendMicro-HouseCallTROJ_GEN.R03BC0PG522
RisingBackdoor.DcRat!8.129D9 (CLOUD)
IkarusTrojan.MSIL.Spy
MaxSecureTrojan.Malware.121218.susgen
FortinetMSIL/Agent.DVA!tr
AVGWin32:RATX-gen [Trj]
PandaTrj/Chgt.AB
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.Dcrat?

Backdoor.Dcrat removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment