Threat Database Backdoors Backdoor.Agent.LEA

Backdoor.Agent.LEA

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 24,480
Threat Level: 60 % (Medium)
Infected Computers: 21
First Seen: June 18, 2024
Last Seen: May 26, 2026
OS(es) Affected: Windows

The detection of Backdoor.Agent.LEA on your system indicates a potential security threat that requires immediate attention. This backdoor threat can compromise the security and integrity of your computer, allowing unauthorized access and potentially leading to further malicious activities. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future occurrences.

What Is Backdoor.Agent.LEA?

Backdoor.Agent.LEA is a type of malware that creates a secret pathway for unauthorized access to your computer. This backdoor can be used by attackers to remotely control your system, steal sensitive information, or install additional malware. The term "backdoor" refers to the malicious program's ability to bypass normal security measures, allowing hackers to access your system without being detected.

How Backdoor.Agent.LEA Operates

Backdoor.Agent.LEA operates by exploiting vulnerabilities in your system's security or by tricking you into installing it. Once installed, it can communicate with its command and control server, receiving instructions and sending stolen data. This malware can also download and install additional malicious programs, making it a significant threat to your system's security and your personal data.

The exact mechanisms used by Backdoor.Agent.LEA to operate can vary, but common tactics include using social engineering to trick users into installing the malware, exploiting software vulnerabilities, or using drive-by downloads from compromised websites. Understanding these tactics is crucial for preventing future infections.

Symptoms of Infection

Symptoms of a Backdoor.Agent.LEA infection can be subtle and may not always be immediately apparent. However, common signs include unusual network activity, slow system performance, and unexpected changes to your system settings. You might also notice that your antivirus software is disabled or that certain programs are not functioning correctly. If you suspect that your system is infected, it is crucial to take action promptly to minimize potential damage.

  • Unexplained changes in system settings or performance
  • Increased network activity without apparent cause
  • Antivirus software is disabled or not functioning
  • Appearance of unknown or suspicious programs

How to Remove Backdoor.Agent.LEA

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove all components of the Backdoor.Agent.LEA malware.
  3. Uninstall any suspicious programs that were installed around the time of the infection. Be cautious and only remove programs that you are certain are malicious or unnecessary.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all remnants of the malware have been removed.

Conclusion

The removal of Backdoor.Agent.LEA requires careful and thorough action to ensure that all components of the malware are eliminated. By following the steps outlined above and maintaining good security practices, such as keeping your software up to date and being cautious with emails and downloads, you can significantly reduce the risk of future infections. Remember, prevention and vigilance are key to protecting your system and personal data from malware threats like Backdoor.Agent.LEA.

Analysis Report

General information

Family Name: Backdoor.Agent.LEA
Signature status: No Signature

Known Samples

MD5: ca6e50504baac68a645c94f71ae1c952
SHA1: 4875d24447ebec03d14183965c79825a8b1abc10
SHA256: 1CBD929D43396A399A6837CCEE871897BD70BFE3E15A21B39F7A03AEFB9D45DE
File Size: 1.33 MB, 1334272 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Pekora Corporation
File Description Pekora
File Version 1, 7, 0, 0
Legal Copyright (C) 2025 Pekora Corporation. All rights reserved.
Original Filename Pekora.exe
Product Name Pekora Bootstrapper
Product Version 1, 7, 0, 0

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 2,614
Potentially Malicious Blocks: 607
Whitelisted Blocks: 2,007
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x 0 0 x 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x x 0 0 x 0 0 0 x x x x x x x x x x x x 0 x x 0 0 0 0 x 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 x 0 0 x x 0 0 0 0 0 0 x x x 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 x x 0 0 0 x 0 0 0 x x x 0 0 0 0 0 0 0 0 0 x x x x x 0 x x x x x x 0 0 0 x x 0 x x 0 x x x x x x x x x x 0 0 0 x 0 0 0 x x x 0 x 0 0 x x 0 x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 x x x 0 x x x 0 0 0 x x x x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x 0 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 x 0 0 x 0 0 x x 0 0 x x 0 0 x 0 0 x x 0 0 0 0 0 x 0 x x x 0 x 0 x 0 0 0 0 x 0 0 x x 0 0 x x 0 0 x x x x x x x x x 0 x x x x x x 0 x x x x 0 0 x x 0 x 0 0 x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x x x x x 0 x 0 x x 0 0 0 x 0 x x x 0 x x x 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 x x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 x 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 x x 0 0 x x 0 x 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x x x x x x 0 x x 0 x x 0 x x 0 0 x x 0 x x 0 x x 0 x x x x x x 0 0 0 0 x x x x x 0 0 0 x x x 0 x x 0 x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x x 0 x 0 x 0 x x x x 0 x 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 x x x x x x 0 0 0 x x x x x x 0 0 0 0 x 0 0 x 0 0 0 x 0 x x x x 0 x x x 0 x x x x 0 0 x 0 0 0 x 0 0 0 x 0 0 0 0 0 x 0 0 x 0 0 0 0 x 0 x x 0 0 x 0 x x 0 x x x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 x 0 x x 0 x 0 0 0 x 0 0 x 0 0 0 0 x x x 0 x x 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x x x x x 0 x x 0 x x x x x x x x x x x x x x x x x x x x x x 0 x x x 0 0 x x x x x x x x x x x x x x x x x x x 0 x x 0 x x x x x x x x x x x x 0 x x x x x x x x 0 0 0 x 0 0 0 0 0 x x x 0 0 0 x 0 x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x x 0 0 0 0 0 0 0 x 0 x x 0 0 x x x 0 0 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 x x 0 x x 0 x x x x 0 x x 0 x x x 0 0 x 0 0 x 0 0 x 0 0 x 0 0 0 0 0 x x x x x x x x x x x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 x 0 x 0 0 x 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x x x 0 x x 0 x 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 x x x x x x x x 0 0 x x x x x 0 x x x x x x 0 x x x 0 x 0 x x x 0 0 0 x 0 0 x x x 0 0 x x x 0 0 0 0 x x x 0 0 0 0 x x 0 x x x x x x x x x x 0 0 x 0 x x x 0 0 0 x x 0 x x 0 x x 0 x x 0 x x 0 0 0 0 0 x x x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 3 1 1 1 1 1 0 0 1 1 1 2 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 2 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 1 0 1 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.LEA

Files Modified

File Attributes
c:\users\user\appdata\local\temp\pjx-cc0cde74.log Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\pekora corporation\pekora::cpath C:\Users\user\AppData\LocalLow\rbxcsettings.rbx RegNtPreCreateKey

Windows API Usage

Category API
Network Winsock2
  • WSASend
  • WSASocket
  • WSAStartup
Network Info Queried
  • GetAdaptersInfo
Network Wininet
  • HttpOpenRequest
  • HttpQueryInfo
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
Network Winhttp
  • WinHttpOpen
Network Winsock
  • closesocket
  • connect
  • freeaddrinfo
  • getaddrinfo

Related Posts

Trending

Most Viewed

Loading...