Threat Database Backdoors Backdoor.Blackrain.A

Backdoor.Blackrain.A

By CagedTech in Backdoors

Threat Scorecard

Threat Level: 60 % (Medium)
Infected Computers: 5
First Seen: February 2, 2022
Last Seen: February 5, 2026
OS(es) Affected: Windows

The detection of Backdoor.Blackrain.A on your system indicates a potential security threat that requires immediate attention. This backdoor threat can compromise the security and integrity of your computer, allowing unauthorized access and potentially leading to further malware infections, data theft, or other malicious activities. It is essential to understand the nature of this threat and take prompt action to remove it and protect your system.

What Is Backdoor.Blackrain.A?

Backdoor.Blackrain.A is a type of malware that operates as a backdoor, which means it can open a secret doorway into your computer system, allowing hackers to access, control, and manipulate your data without your knowledge or consent. This type of threat is particularly dangerous because it can be used to install additional malware, steal sensitive information, or use your computer as a botnet to carry out malicious activities.

How Backdoor.Blackrain.A Operates

Backdoor.Blackrain.A, like other backdoor threats, is designed to remain stealthy and evade detection by traditional security software. It can be spread through various means, including exploited vulnerabilities, phishing attacks, or drive-by downloads. Once installed, it can communicate with its command and control servers to receive instructions and transmit stolen data. The exact mechanisms of how Backdoor.Blackrain.A operates can vary, but its primary goal is to provide unauthorized access to your computer system.

Symptoms of Infection

Identifying a backdoor infection can be challenging because these threats are designed to be stealthy. However, some common symptoms may include unusual network activity, slow system performance, unexpected changes to system settings, or the appearance of unfamiliar programs or files. If you suspect that your system has been infected with Backdoor.Blackrain.A or any other malware, it is crucial to take immediate action to mitigate the threat.

How to Remove Backdoor.Blackrain.A

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove Backdoor.Blackrain.A and any other malware that may be present.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed around the time of the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings that the malware may have altered.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that the threat has been completely removed.

Conclusion

Removing Backdoor.Blackrain.A requires careful and immediate action to prevent further damage to your system and to protect your sensitive data. By following the steps outlined above and maintaining good security practices, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when clicking on links or opening attachments, you can significantly reduce the risk of malware infections. Remember, vigilance and proactive measures are key to protecting your digital security in today's evolving threat landscape.

Analysis Report

General information

Family Name: Backdoor.Blackrain.A
Packers: UPX
Signature status: No Signature

Known Samples

MD5: df87a63ebba0e09d8c5498415d294093
SHA1: d7f713ee11e7490febc3cb4d8dbb524e955c9a18
SHA256: 34350039BF0DBC13BC51A08B2C46B1B3BBD6DFCECFF1B2E0854B4C519190BC9A
File Size: 490.32 KB, 490320 bytes
MD5: 080d012ee6f84cbbef1532ec602286e8
SHA1: 3853f5c9fd65214919c4c6a8b338ebdc05deb6d7
SHA256: 1EE0556809BC1A2A470188D993D8BD1597D3BB8B87A3B07477B21DFC0F47F074
File Size: 467.28 KB, 467280 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments http://www.metaquotes.net
Company Name MetaQuotes Software Corp.
File Description Setup
File Version 5.0.0.1172
Internal Name Setup
Legal Copyright © 2001-2015, MetaQuotes Software Corp.
Legal Trademarks MetaTrader
Original Filename Setup
Product Name Setup
Product Version 5.0.0.1172

File Traits

  • 2+ executable sections
  • HighEntropy
  • Installer Version
  • packed
  • x86

Block Information

Total Blocks: 1,023
Potentially Malicious Blocks: 10
Whitelisted Blocks: 578
Unknown Blocks: 435

Visual Map

? 0 0 ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 x 0 0 0 0 ? 0 0 0 0 ? 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 ? 0 0 ? ? 0 ? ? 0 0 0 ? 0 0 ? x 0 0 0 0 0 0 ? 0 0 x 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 ? 0 ? ? 0 ? ? x 0 ? ? ? 0 0 ? 0 ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 x 0 0 ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 0 ? ? 0 0 ? 0 ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? 0 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 1 0 0 0 1 0 1 0 0 1 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 2 1 0 0 0 0 1 0 0 1 0 0 0 1 3 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 2 2 1 0 0 0 0 0 1 0 0 0 0 0 0 1 1 0 0 1 1 0 0 1 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 0 ? ? 0 ? 0 ? ? ? 0 ? ? ? ? ? ? 0 ? ? 0 ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? 0 0 ? 0 0 x ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? 0 ? ? 0 ? 0 x ? 0 x ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\harddisk0\dr0 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\google\chrome\user data\default\pepper data\shockwave flash\writableroot\#sharedobjects Generic Write,Read Attributes
c:\users\user\appdata\roaming\macromedia\flash player\#sharedobjects Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\metaquotes software::id 058C6979-04A2-I RegNtPreCreateKey
HKLM\software\metaquotes software::id F9E38006-4827-I RegNtPreCreateKey

Windows API Usage

Category API
Network Winsock2
  • WSAStartup
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Network Winhttp
  • WinHttpConnect
  • WinHttpOpen
  • WinHttpOpenRequest

Related Posts

Trending

Most Viewed

Loading...