Detection name
Txt.Backdoor.MetasploitPayload-9874938-0
Backdoor · Text / scripts
- Risk
- Critical
- Verdict
- Malware
Name breakdown
- TxtPlatform · Text / scripts
- BackdoorType · Backdoor
- MetasploitPayloadName · Metasploit
- 9874938Signature ID
- 0Revision
Overview
A signature that detects a Backdoor targeting Text / scripts.
Malware that opens a hidden "back door" so an attacker can control the computer remotely — used to steal data or deliver more malware.
About Metasploit
Metasploit is an open-source penetration testing framework developed by Rapid7. It's used in legitimate security assessments, but the payloads it generates (such as Meterpreter) are also used in real attacks. Unless you created the file yourself for testing, treat it as a backdoor that allows remote control.
What to do if it's detected
- 01Don't open or run the file — delete it.
- 02If you already opened or ran it, disconnect the device from the network and run a full scan with your security software.
- 03Change your passwords from a different, trusted device and check for suspicious logins.
- 04If it's a work device, report it to your IT department.
Could it be a false positive?
ClamAV false positives are uncommon but not impossible. If it's a file you need and the detection seems wrong, use the link on the result screen to check other engines on VirusTotal.
Check your own files
Drop a file into FileScan to scan it with ClamAV. No sign-up, and your file is never stored.
Scan a file →