Backdoor

Backdoor.RAT.Venom (file analysis)

Malware Removal

The Backdoor.RAT.Venom is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.RAT.Venom virus can do?

  • Authenticode signature is invalid

How to determine Backdoor.RAT.Venom?


File Info:

name: 6A79E63153F793A8713A.mlw
path: /opt/CAPEv2/storage/binaries/b77e4af833185c72590d344fd8f555b95de97ae7ca5c6ff5109a2d204a0d2b8e
crc32: 23572F49
md5: 6a79e63153f793a8713a591c80167cb3
sha1: 89f104911e2a54d612a791940501f74687b39046
sha256: b77e4af833185c72590d344fd8f555b95de97ae7ca5c6ff5109a2d204a0d2b8e
sha512: e500bb50d8ba72eb7e72e1073ca401509e51b86ea0e26df88d896b71b84f91ef5543d39c4fe1336356556e775a683d0142e9c09f93605a1056116f5e84d831fe
ssdeep: 1536:1ULkcxVKpC6yPMVKe9VdQuDI6H1bf/cLoBQzcGLVclN:1UocxVENyPMVKe9VdQsH1bfDQfBY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FB735B013BE8CD2AE2AD47B9ACF255074EF4D1576512CE5E3CC440CD5A67BC58A037EA
sha3_384: e079397aeffeffb8c9e931cd7791972dec452ed7db99813962718d7290c767eb84f71706d0be2c47b1fbea0026dc6cb6
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-02-08 22:10:28

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription:
FileVersion: 6.0.1
InternalName: ClientAny.exe
LegalCopyright:
LegalTrademarks:
OriginalFilename: ClientAny.exe
ProductName:
ProductVersion: 6.0.1
Assembly Version: 6.0.1.0

Backdoor.RAT.Venom also known as:

BkavW32.Common.DA2E73B1
LionicTrojan.Win32.Agent.Y!c
MicroWorld-eScanTrojan.GenericKDZ.102657
ClamAVWin.Packed.Razy-9807129-0
CAT-QuickHealTrojan.GenericFC.S30117478
ALYacBackdoor.RAT.Venom
MalwarebytesGeneric.Trojan.MSIL.DDS
VIPRETrojan.GenericKDZ.102657
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
AlibabaTrojan:Any/Generic.a
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.MSIL_Heur.B
CyrenW32/Trojan.IML.gen!Eldorado
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Agent.CFQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderTrojan.GenericKDZ.102657
SUPERAntiSpywareTrojan.Agent/Gen-MSILZilla
AvastWin32:DropperX-gen [Drp]
TencentTrojan.MSIL.Agent.16000593
EmsisoftTrojan.GenericKDZ.102657 (B)
F-SecureHeuristic.HEUR/AGEN.1307334
DrWebBackDoor.AsyncRATNET.1
ZillyaTrojan.Agent.Win32.3646835
TrendMicroBackdoor.Win32.ASYNCRAT.YXDHKZ
McAfee-GW-EditionBehavesLike.Win32.Generic.lm
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.6a79e63153f793a8
SophosTroj/VenomRat-A
SentinelOneStatic AI – Malicious PE
GDataMSIL.Trojan-Stealer.Keylogger.BA
JiangminTrojan.MSIL.aoink
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1307334
MAXmalware (ai score=82)
Antiy-AVLTrojan/MSIL.AsyncRAT
Kingsoftmalware.kb.c.1000
ArcabitTrojan.Generic.D19101
ViRobotTrojan.Win.Z.Agent.75776.RD
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
MicrosoftTrojan:MSIL/AsyncRAT.S!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Agent.C5382940
McAfeeGenericRXVS-NQ!6A79E63153F7
VBA32TScope.Trojan.MSIL
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallBackdoor.Win32.ASYNCRAT.YXDHKZ
RisingBackdoor.AsyncRAT!1.C678 (CLASSIC)
YandexTrojan.Agent!JIdkd4U91G0
IkarusBackdoor.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.CTE!tr
BitDefenderThetaGen:NN.ZemsilF.36738.em0@amgKwGe
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS

How to remove Backdoor.RAT.Venom?

Backdoor.RAT.Venom removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment