Threat Database Backdoors Backdoor.PSW.Agent.LDA

Backdoor.PSW.Agent.LDA

By CagedTech in Backdoors

Threat Scorecard

Threat Level: 60 % (Medium)
Infected Computers: 21
First Seen: November 11, 2024
Last Seen: February 25, 2026
OS(es) Affected: Windows

The detection of Backdoor.PSW.Agent.LDA on your system indicates a serious security threat that requires immediate attention. This backdoor threat can potentially allow unauthorized access to your computer, compromising your personal data and security. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Backdoor.PSW.Agent.LDA?

Backdoor.PSW.Agent.LDA is a type of malware that creates a secret doorway into your computer system, allowing hackers to access your files, steal sensitive information, and take control of your machine. This backdoor threat can be particularly dangerous as it can remain hidden and operate undetected, making it challenging to identify and remove. The name "Backdoor.PSW.Agent.LDA" suggests that it is a backdoor threat, but the exact nature and behavior of this specific malware are not well-defined, emphasizing the need for a thorough removal process.

How Backdoor.PSW.Agent.LDA Operates

Backdoor threats like Backdoor.PSW.Agent.LDA typically operate by exploiting vulnerabilities in software or using social engineering tactics to trick users into installing them. Once installed, they can create a communication channel with their command and control servers, allowing hackers to send commands and receive stolen data. These threats can also spread through infected software downloads, infected websites, or infected email attachments. Understanding how backdoor threats operate is crucial in preventing their spread and removing them effectively.

Symptoms of Infection

Identifying the symptoms of a backdoor infection can be challenging, as these threats are designed to remain hidden. However, some common indicators of a backdoor infection include unusual network activity, slow system performance, and unfamiliar programs or icons on your computer. You may also notice that your computer is behaving erratically, such as crashing or freezing frequently. If you suspect that your system is infected with Backdoor.PSW.Agent.LDA, it is essential to take immediate action to remove the threat and prevent further damage.

How to Remove Backdoor.PSW.Agent.LDA

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a safe removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs associated with Backdoor.PSW.Agent.LDA.
  3. Uninstall any suspicious programs or software that may be related to the backdoor threat. Be cautious when uninstalling programs, as some may be legitimate or required by your system.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons that may be associated with the backdoor threat.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that the threat has been completely removed.

Conclusion

Removing Backdoor.PSW.Agent.LDA from your system requires a thorough and careful approach to ensure that the threat is completely eliminated. By following the steps outlined above and using reputable anti-malware tools, you can help protect your computer and personal data from the risks associated with this backdoor threat. Remember to always be cautious when downloading software, opening email attachments, or clicking on links from unknown sources, as these are common ways that backdoor threats can infect your system. By staying vigilant and taking proactive steps to secure your computer, you can help prevent future infections and keep your personal data safe.

Analysis Report

General information

Family Name: Backdoor.PSW.Agent.LDA
Signature status: No Signature

Known Samples

MD5: 356172146fc8c6d37f067175dcc9d9db
SHA1: 2a5f30673f3099ab9d712897c056786492474551
SHA256: 072EE0C0C6B1D34D420EDE748A2A81DE1B48B59ED956E415A7DBC9FE0502A422
File Size: 1.99 MB, 1992192 bytes
MD5: 8119ca3a8ecf82784604281144657f9f
SHA1: 24eee9567c957d3d5fdc7b3a9876f6bf00fbd13a
SHA256: 51BF06AE54849861CC44A755BF58968BFFB44530843CFF05BD62E551C1C2161C
File Size: 1.97 MB, 1966592 bytes
MD5: e381c33516f64a87ddbf869240eac84b
SHA1: 724ca892868bc7fa7c36075f29af7e5b8f755c3c
SHA256: 4DBA30B86F6576CF4D043F460317E3BEA356A1FD68DBB522E492F965ED22116E
File Size: 2.06 MB, 2059264 bytes
MD5: 88ae6faad5002b4a88340b02fbb11c78
SHA1: 4ecda3a9f3ee9cab8d06dff80184ebd490c96afe
SHA256: 5E6DFFEF90710A2FFE0BAF6D2C238F67A550198AED112D73D01ED94E78221E47
File Size: 2.30 MB, 2300016 bytes
MD5: 3ab72d0f42b6c0a582298d778df41d41
SHA1: e4d2597534987416d72023af1d0b4e0aa2386ea9
SHA256: BF0C1155122F8C87E747E40FFE999423DFBF191D6E3919E06FCAADCAD472A5B2
File Size: 2.03 MB, 2032640 bytes
Show More
MD5: a7116b05447ce0a9dadaacf3a87c3694
SHA1: 12f53424032494a383bd2ba031099bf5dcdb7199
SHA256: 99C98AA346D03D789FE8CC3762FC15BA173D6A9B932FA4CF5FAF92B876D7DACA
File Size: 1.97 MB, 1966080 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Digital Signatures

Signer Root Status
Areeb Ahmed Code Signing LLC Areeb Ahmed Code Signing LLC Self Signed

File Traits

  • dll
  • Pastebin
  • x64

Block Information

Total Blocks: 6,466
Potentially Malicious Blocks: 426
Whitelisted Blocks: 5,468
Unknown Blocks: 572

Visual Map

? 0 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 ? 1 0 0 1 0 0 0 0 0 0 1 0 0 1 0 0 1 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 1 0 0 1 0 0 0 0 0 1 0 0 0 0 0 1 0 0 1 0 0 1 0 0 0 1 0 0 0 0 0 1 0 0 1 0 0 0 0 0 1 0 0 1 0 0 x 0 0 0 0 0 0 x x x x x x x x 0 ? 0 0 0 ? 0 x 0 x 0 0 0 1 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 x 0 0 ? 0 0 x ? ? 0 x x 0 0 0 0 0 0 0 ? 0 ? ? 0 ? ? ? ? ? 0 ? 0 0 0 ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? 0 ? ? 0 ? 0 ? ? x ? ? x x 1 0 0 0 0 0 0 0 x ? 0 ? ? 0 ? 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 ? ? 0 0 0 ? 0 0 0 0 ? ? 0 ? ? ? 0 0 0 ? ? 0 0 0 0 ? 0 ? 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 x x ? 0 0 ? x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? 0 0 ? 0 0 0 0 0 ? x 0 0 0 x x x 0 0 0 ? 0 0 0 ? ? 0 0 0 x 0 0 0 x x x x ? 0 x 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 1 0 x 0 0 0 0 0 0 0 0 1 0 0 0 0 x 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 x ? 0 x 0 0 1 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 ? x 0 x x ? ? 0 0 0 0 1 0 ? ? 0 0 0 0 1 0 0 0 0 0 0 1 0 x x 0 0 x x 0 x 0 0 x 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 ? 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 ? x x x x 0 0 0 0 0 ? x x x x x x x 0 0 0 0 x ? x x 0 0 0 ? x 0 0 x x 0 1 ? x 0 0 ? ? ? x ? 0 ? ? 0 x 0 0 0 0 0 0 0 0 ? ? x ? ? x 0 x x 0 0 0 0 0 0 ? 0 ? 0 x 0 0 0 0 0 x 1 x 0 x 0 0 x 0 x x 0 ? x x x x 0 0 0 0 ? ? ? 0 ? x x x ? x ? x x 0 x 0 x 0 0 0 x x x x x 0 ? x x ? x x x x x x x 0 0 0 x x 0 0 0 x 0 0 ? 0 x 0 0 0 x 0 x 0 0 0 x 0 0 x 0 0 0 1 0 0 0 0 0 0 0 ? ? ? ? x x x 0 x ? 0 x 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 0 0 x 0 0 x x 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 ? 0 0 0 x 0 0 0 0 0 x 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 x 0 0 0 0 0 ? x 0 0 0 0 0 0 0 1 ? ? 0 0 0 0 ? 0 0 x 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 ? ? ? 0 x x x 0 0 x x x x 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 x x 0 0 0 0 0 0 ? x ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 x 0 x x x 0 0 0 0 0 ? 0 x ? 0 0 0 1 x 0 0 x x 0 0 ? 0 0 0 ? 0 0 0 x 0 0 x 0 0 0 0 0 ? 0 0 0 x 0 x 0 0 x 0 0 0 0 x x 0 0 0 0 0 x x x 0 0 x ? 0 x ? 0 x x x 0 x ? x 0 ? x x 0 0 x x x x 0 ? ? ? 0 ? ? ? ? 0 ? x x ? 0 ? 0 0 0 0 0 x x x x 0 0 x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 0 0 x x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 0 x 0 x 0 x 0 0 x 0 0 x 0 x 0 x x x x 0 0 x x 0 0 x x 0 0 x x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 1 0 0 0 0 x 0 0 0 x x 0 0 0 x ? ? 0 ? x 0 0 0 0 x ? 0 0 ? ? ? 0 x x 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 ? x 0 x ? 0 0 0 ? ? 0 ? ? 0 0 0 ? ? 0 0 0 ? ? 0 0 ? 0 ? ? ? 0 ? ? ? x x ? x x 0 0 ? ? 0 0 ? 1 0 0 x x x x x x 0 0 0 0 0 0 ? ? ? 0 x ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 x x 0 0 x x x 0 x x 0 0 x x 0 0 0 0 0 0 0 0 x x x 0 x x x 0 0 x x 0 0 ? ? ? 0 0 0 0 0 0 x 0 x x 0 0 0 x x 0 0 0 x x x ? 0 0 0 0 0 x ? 0 0 0 x 0 0 0 0 ? ? x 0 0 ? 0 ? 0 0 0 0 x 0 0 0 x 0 0 0 0 x 0 0 ? 0 0 0 x ? 0 0 0 0 0 ? 0 0 0 0 0 x 0 0 0 0 0 ? ? 0 x ? 0 0 0 0 x x 0 0 0 0 ? 0 x x ? x 0 0 x x ? x 0 0 x x x x ? x 0 0 0 x x 0 0 0 0 0 0 ? 0 0 0 0 1 0 0 0 0 0 0 x 0 0 0 0 0 0 0 ? 0 0 0 x ? 0 ? 0 x 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 0 0 0 0 0 x ? 0 0 ? 0 0 0 0 ? 0 x 0 0 0 0 0 0 0 0 x ? x 0 x x 0 ? 0 0 x 0 ? 0 0 0 0 0 0 0 0 x x ? 0 0 0 0 0 0 0 0 0 0 ? 0 x x 0 x ? 0 0 0 0 0 0 0 0 x 0 x x 0 x 0 x 0 ? 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 1 x 0 0 0 x 0 0 x ? 1 0 0 ? ? 0 0 0 0 0 ? 0 0 ? x x 0 x ? 0 0 x ? 1 0 0 x ? 0 0 0 0 0 0 0 0 0 0 ? x ? ? ? x 0 0 0 0 0 0 x ? 0 0 0 0 0 0 0 x ? 0 x x 0 0 x ? 0 0 x x 0 0 0 0 x x x 0 0 x 0 0 0 x x 0 0 x 0 0 0 ? 0 0 0 0 x x x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 ? 0 0 x 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\yubx_4884 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\yubx_5012 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\yubx_5516 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\yubx_7584 Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateNamedPipeFile
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueryWnfStateNameInformation
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetSystemInformation
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUpdateWnfStateData
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiRestoreDC
  • win32u.dll!NtGdiSaveDC
  • win32u.dll!NtGdiSelectBitmap
  • win32u.dll!NtGdiSetDIBitsToDeviceInternal
  • win32u.dll!NtUserBuildHwndList
  • win32u.dll!NtUserCallTwoParam
  • win32u.dll!NtUserCreateEmptyCursorObject
  • win32u.dll!NtUserCreateWindowEx
  • win32u.dll!NtUserDestroyWindow
  • win32u.dll!NtUserFindExistingCursorIcon
  • win32u.dll!NtUserGetAncestor
  • win32u.dll!NtUserGetClassInfoEx
  • win32u.dll!NtUserGetClassName
  • win32u.dll!NtUserGetDC
  • win32u.dll!NtUserGetGUIThreadInfo
  • win32u.dll!NtUserGetIconInfo
  • win32u.dll!NtUserGetIconSize
  • win32u.dll!NtUserGetImeInfoEx
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetObjectInformation
  • win32u.dll!NtUserGetProcessWindowStation
  • win32u.dll!NtUserGetProp
  • win32u.dll!NtUserGetThreadDesktop
  • win32u.dll!NtUserGetThreadState

14 additional items are not displayed above.

Encryption Used
  • BCryptOpenAlgorithmProvider

Related Posts

Trending

Most Viewed

Loading...