Backdoor

Backdoor.Win64.Meterpreter.ck (file analysis)

Malware Removal

The Backdoor.Win64.Meterpreter.ck is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win64.Meterpreter.ck virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • A script process created a new process
  • Attempts to execute suspicious powershell command arguments

How to determine Backdoor.Win64.Meterpreter.ck?


File Info:

name: C6781AAF3A8C7E9B5C5C.mlw
path: /opt/CAPEv2/storage/binaries/000350aa53438d1e009bcf96306f557baa4f2e0bf1507a2791db38af84edd7ee
crc32: 88E1F1B9
md5: c6781aaf3a8c7e9b5c5cbae6a9f212db
sha1: b8fcfe5f5dcdeb2724c1df30005b3ffd8f46a7ae
sha256: 000350aa53438d1e009bcf96306f557baa4f2e0bf1507a2791db38af84edd7ee
sha512: 83ddda03da0028ee5f228d9bfd8306a09ef391ead84bb4e35f005952ab8628bd7ed0dd2abbdc6ff166f40c7a38e8c818dcd60ac8f1c02a1df3f89408d71b9d30
ssdeep: 98304:c2cPK88KQUvoJgTcm5MfGxKsAmv6TgGXepu1e6wqY6fuN6Z5a7:HCKpkv+g5eaFAmv60GupujLfm6za7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CE161212B3D5D032FFABA2739B69F6055ABD78240133951F13981D69BCB02B1263E763
sha3_384: 03a71e10d2c93d3d20815b0cca5e52f1237b461744820f39b4ecd1b496c3f6167b21e27b8c6961488b0d2a344e3f8c1a
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2021-12-21 00:01:25

Version Info:

Translation: 0x0809 0x04b0

Backdoor.Win64.Meterpreter.ck also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebBackDoor.Meterpreter.155
MicroWorld-eScanAIT:Trojan.Nymeria.4564
ALYacTrojan.GenericKD.35378294
CylanceUnsafe
CyrenW64/Trojan.QUHY-4976
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_GEN.R002C0WKM21
ClamAVWin.Coinminer.Generic-7151253-0
KasperskyBackdoor.Win64.Meterpreter.ck
BitDefenderAIT:Trojan.Nymeria.4564
NANO-AntivirusTrojan.Win64.Meterpreter.imvjgj
AvastBV:Miner-HA [PUP]
RisingHackTool.VulnDriver/x64!1.D7DB (CLASSIC)
Ad-AwareAIT:Trojan.Nymeria.4564
SophosXMRig Miner (PUA)
TrendMicroTROJ_GEN.R002C0WKM21
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
FireEyeGeneric.mg.c6781aaf3a8c7e9b
EmsisoftAIT:Trojan.Nymeria.4564 (B)
IkarusTrojan.Win32.Masson
GDataTrojan.GenericKD.35378294 (2x)
AviraHEUR/AGEN.1144864
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.31797C6
ArcabitAIT:Trojan.Nymeria.D11D4
MicrosoftTrojan:Win64/DisguisedXMRigMiner
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R424561
MalwarebytesMalware.AI.625346215
APEXMalicious
eGambitUnsafe.AI_Score_99%
FortinetW64/Meterpreter.CDK!tr.bdr
AVGBV:Miner-HA [PUP]
Cybereasonmalicious.f3a8c7
MaxSecureTrojan.Malware.300983.susgen

How to remove Backdoor.Win64.Meterpreter.ck?

Backdoor.Win64.Meterpreter.ck removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment