Backdoor

BScope.Backdoor.RmRAT (file analysis)

Malware Removal

The BScope.Backdoor.RmRAT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Backdoor.RmRAT virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine BScope.Backdoor.RmRAT?


File Info:

name: 871709B35FBED5A7B4FD.mlw
path: /opt/CAPEv2/storage/binaries/cb71167fa6ac9ab2bc034a996cc32c5c2d55c110eac992b55217f326d68360ab
crc32: 1CB6FD6F
md5: 871709b35fbed5a7b4fd794150d32d87
sha1: 137b7233d775f55ae31843d15f5e675dc83dd320
sha256: cb71167fa6ac9ab2bc034a996cc32c5c2d55c110eac992b55217f326d68360ab
sha512: 580fe3b3873fb2d7bfd705cd23e0ad6ba79a87947ee3dcacd4718fb22a6ff5ee0298714fa492a6c3b15f2a88bc680e3b4a2028a87ec1e849ca755eba3a5d8a4c
ssdeep: 3072:DvSILBLeQECG0MjSbY/6kiFmujqUQ5HHLyVYDRePIAxyBW:7SgBLefb5cFmuNQ5nLibPIAp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T150643A13A2E03D59E6266B328F2EC6EC775DF5508E39776932189E3F0870176C163BA1
sha3_384: 4e6030cf370287810fc2a2436cb163ca2bbe0ae57a7e62a2e1a7ca1c574a4d212cf0a805b5f7a1786cc2be5c224be617
ep_bytes: e81d350000e979feffff8bff558bec51
timestamp: 2022-05-17 02:46:14

Version Info:

FileDescription: Silvuple
LegalCopyright: Copyright (C) 2022, Vombat
OriginalFilename: petshop.exe
ProductsVersion: 23.51.62.52
ProductName: Moran
ProductionVersion: 77.85.94.62
Translation: 0x05bf 0x0ad4

BScope.Backdoor.RmRAT also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
ClamAVWin.Packer.pkr_ce1a-9980177-0
CAT-QuickHealRansom.Stop.P5
McAfeeLockbit-FSWW!871709B35FBE
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Backdoor.Win32.Agent.gen
TencentTrojan.Win32.Obfuscated.gen
McAfee-GW-EditionBehavesLike.Win32.Lockbit.dh
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.871709b35fbed5a7
SophosML/PE-A
SentinelOneStatic AI – Suspicious PE
ZoneAlarmVHO:Backdoor.Win32.Agent.gen
MicrosoftRansom:Win32/StopCrypt!ml
GoogleDetected
AhnLab-V3CoinMiner/Win.Glupteba.R504956
Acronissuspicious
VBA32BScope.Backdoor.RmRAT
Cylanceunsafe
RisingTrojan.Generic@AI.100 (RDML:al8koeJFSO1rmTWABSZ7WQ)
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HFSR!tr
DeepInstinctMALICIOUS

How to remove BScope.Backdoor.RmRAT?

BScope.Backdoor.RmRAT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment