Backdoor

Backdoor.Win32.Mokes.anrp (file analysis)

Malware Removal

The Backdoor.Win32.Mokes.anrp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Mokes.anrp virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Kannada
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Mokes.anrp?


File Info:

crc32: 88A1452B
md5: 218f3658bb016cab8adf1554c511046e
name: 218F3658BB016CAB8ADF1554C511046E.mlw
sha1: 4cf4fddb690964b269be7c651e3dd76942e89c02
sha256: 7ab13788b1669baa129c07a04d9f639e5d48dc1b814df790baab256359d3fef6
sha512: e6b4c77e5e0c044d142268c6638584c33bf847b29f5b3ce21152762aa1ff9c18ba2dfcc60162a6d8c5ddc354b7215b3e0e1b746aee9a6adf52ca095875d36174
ssdeep: 3072:69ItknVm57fbfPdzSj9SXY04vSXToaz2p:aM7fbflzSjQYzv7D
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: bomgpiaruci.iwa
ProductVersion: 15.54.32.51
Copyright: Copyrighz (C) 2021, fudkagat
Translation: 0x0115 0x0456

Backdoor.Win32.Mokes.anrp also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00589c9c1 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.33262
CynetMalicious (score: 100)
ALYacGen:Variant.Fragtor.37347
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Mokes.eb5130ea
K7GWTrojan ( 00589c9c1 )
Cybereasonmalicious.b69096
CyrenW32/Kryptik.FOQ.gen!Eldorado
SymantecPacked.Generic.528
ESET-NOD32a variant of Win32/Kryptik.HNDU
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyBackdoor.Win32.Mokes.anrp
BitDefenderGen:Heur.Mint.Titirez.ju0@ifdTgzmG
MicroWorld-eScanGen:Heur.Mint.Titirez.ju0@ifdTgzmG
Ad-AwareGen:Heur.Mint.Titirez.ju0@ifdTgzmG
SophosML/PE-A + Troj/Krypt-BO
BitDefenderThetaGen:NN.ZexaF.34236.ju0@aedTgzmG
TrendMicroTROJ_GEN.R002C0RK221
McAfee-GW-EditionBehavesLike.Win32.Trojan.ch
FireEyeGeneric.mg.218f3658bb016cab
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.MalwareCrypter.atblg
eGambitUnsafe.AI_Score_97%
MicrosoftTrojan:Win32/Azorult.RT!MTB
GDataGen:Heur.Mint.Titirez.ju0@ifdTgzmG
AhnLab-V3Infostealer/Win.SmokeLoader.R448265
Acronissuspicious
McAfeeGenericRXQO-MO!218F3658BB01
MAXmalware (ai score=83)
VBA32Malware-Cryptor.2LA.gen
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.DA22 (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FMYB!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Backdoor.Win32.Mokes.anrp?

Backdoor.Win32.Mokes.anrp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment