Threat Database Backdoors Backdoor.Spy.Agent.FSB

Backdoor.Spy.Agent.FSB

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 26,882
Threat Level: 60 % (Medium)
Infected Computers: 4
First Seen: May 11, 2026
Last Seen: July 28, 2026
OS(es) Affected: Windows

The detection of Backdoor.Spy.Agent.FSB indicates that a potentially malicious program has been identified on your system. This name suggests it is a backdoor threat, which is a type of malware that allows unauthorized access to a computer system. Backdoors can be used for a variety of malicious purposes, including spying, data theft, and the installation of additional malware.

What Is Backdoor.Spy.Agent.FSB?

Backdoor.Spy.Agent.FSB is a detected threat that implies the presence of a backdoor on your system. The specifics of this threat are not detailed in the detection name itself, but it is clear that it has the potential to allow unauthorized access and control over your computer. Backdoors like this are often installed without the user's knowledge or consent, and they can be extremely difficult to detect and remove without the help of specialized security software.

How Backdoor.Spy.Agent.FSB Operates

Backdoors operate by creating a secret pathway into your computer system, allowing hackers to access your files, steal sensitive information, or use your computer for malicious activities without your knowledge. They can be installed through various means, such as exploited vulnerabilities in software, phishing attacks, or by being bundled with other malicious programs. Once installed, a backdoor can communicate with its command and control servers to receive instructions, which can include commands to steal data, install additional malware, or participate in distributed denial-of-service (DDoS) attacks.

Symptoms of Infection

Symptoms of a backdoor infection can be subtle and may not always be immediately apparent. However, some common signs include unusual network activity, slow system performance, unexplained changes to system settings, and the appearance of unfamiliar programs or files. If you suspect that your system has been infected with Backdoor.Spy.Agent.FSB or any other malware, it is crucial to take immediate action to protect your data and system integrity.

How to Remove Backdoor.Spy.Agent.FSB

  1. Enter Safe Mode with Networking to prevent the malware from interfering with the removal process. This mode allows you to use the internet to download removal tools while limiting the malware's ability to run.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. These tools are designed to detect and remove malware, including backdoors like Backdoor.Spy.Agent.FSB.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and only remove programs that you are certain are not necessary for your system's operation.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings. This can help remove any malicious extensions or settings that the malware may have installed.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed. Repeat this process until no more threats are detected.

Conclusion

The detection and removal of Backdoor.Spy.Agent.FSB require careful attention to ensure that your system is thoroughly cleaned and protected against future infections. By understanding how backdoors operate and following the steps outlined for removal, you can help safeguard your system and data. Remember, prevention is key, so always be cautious when clicking on links, opening email attachments, and installing software from the internet. Keeping your operating system, software, and security tools up to date is also crucial in protecting against the latest threats.

Analysis Report

General information

Family Name: Backdoor.Spy.Agent.FSB
Signature status: No Signature

Known Samples

MD5: 7cb3825fe1826ca8dc12846e8b70a735
SHA1: bfce02be8dc226e0336a4c53bbef0ccd9acb06ef
SHA256: 84A623C64DBAD85610063115A078802D086490255707E769C24C0209E633ED07
File Size: 1.79 MB, 1788416 bytes
MD5: 08a565a562c19e84cc952534ae15cd3c
SHA1: 1b50330f094c688b947803cba4ee4dda08eb5fcf
SHA256: BD5E9E0E050AA8347431135791645FACB8DF40AD462E617EB0406F2FE8B5B78A
File Size: 1.79 MB, 1788416 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • HighEntropy
  • No Version Info
  • ntdll
  • x64

Block Information

Total Blocks: 5,528
Potentially Malicious Blocks: 722
Whitelisted Blocks: 4,733
Unknown Blocks: 73

Visual Map

0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 x x 0 0 0 x x 0 0 0 0 x 0 0 0 0 0 x x 0 ? 0 ? 0 0 x 0 0 0 0 0 0 x x 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 ? 0 0 0 x 0 0 x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x x ? 0 ? 0 ? ? ? ? ? 0 x 0 ? ? x 0 0 0 ? ? x 0 0 x ? ? 0 ? ? 0 0 0 0 x x 0 0 ? 0 0 0 0 0 0 ? 0 x 0 x 0 0 0 0 0 0 0 0 x x x ? 0 x x 0 0 0 0 0 0 0 ? 0 0 0 x ? 0 ? ? ? ? 0 0 0 0 0 x 0 0 0 0 x 0 x x x 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 x ? 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 0 x 0 0 0 0 x 0 0 x 0 x 0 0 0 0 0 0 x x ? ? ? x x x x 0 x x x 0 ? x ? x 0 x 0 x 0 ? x 0 x ? ? ? x 0 x 0 x x ? 0 0 0 0 0 0 ? x x 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 x 0 0 0 0 0 x x x 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x 0 x 0 x 0 0 x 0 0 x x 0 0 x x 0 0 x x 0 0 x x 0 0 x x 0 0 x x x x x 0 0 x x 0 0 x ? 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 ? 0 0 0 0 0 0 x x x x x x 0 x 0 0 x 0 0 0 x 0 x x x 0 0 0 0 0 0 0 0 x x x 0 x 0 0 x x x x x x 0 x x x x 0 0 0 0 x x x x 0 x x x x x x x x x x x x x 0 0 x x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x 0 0 0 x 0 0 x 0 x 0 x ? x x ? x 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 x 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 x x x x 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 x x x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 x 0 x x 0 0 0 0 x 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 ? x 0 ? ? 0 ? 0 0 x 0 0 0 0 0 ? ? 0 x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 ? 0 0 ? 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x x 0 0 0 ? 0 0 x 0 0 x x 0 0 ? ? ? 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 x 0 0 0 0 x 0 0 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 ? ? x 0 0 0 0 x 0 ? ? x ? ? ? x ? ? 0 ? x 0 x 0 0 x x x 0 0 0 x 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 x 0 x 0 0 0 0 0 0 0 x 0 0 x x x ? x 0 x ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 ? ? x 0 x x x x x x 0 x x x 0 0 0 0 x x x 0 0 0 0 0 x 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x x x x 0 x x x x x x x x 0 0 x x 0 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 x x 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 x x x x 0 0 0 0 0 0 0 x x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x x x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x 0 x x 0 0 x 0 x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x x x x x 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x 0 0 x 0 0 0 0 x 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Spy.Agent.FSB
  • Trojan.Filecoder.Gen.FF

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\bootmgr Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\dumpstack.log Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\dumpstack.log.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\rware_id.dat Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 爭톅華ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 爭톅華ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 팥톇華ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 㝍톊華ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 韬톌華ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 逸톎華ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 뼚톓華ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ⅂톖華ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 繹툔華ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe �sҴ�� RegNtPreCreateKey
Show More
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 㹫퉶華ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ꄃ퉸華ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ꄃ퉸華ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 斆퉽華ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ~ (��� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ��,��� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe P�3��� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe �D��� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe �-N��� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe "�c��� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe ����� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe f���� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe �f-��� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ����� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe �u���� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ����� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAccessCheckByType
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
Show More
  • ntdll.dll!NtAlpcOpenSenderProcess
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFindAtom
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtImpersonateAnonymousToken
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId

8 additional items are not displayed above.

User Data Access
  • GetComputerNameEx
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • IsDebuggerPresent
Other Suspicious
  • AdjustTokenPrivileges
Process Terminate
  • TerminateProcess

Shell Command Execution

C:\WINDOWS\system32\taskkill.exe "taskkill" /F /IM sqlbrowser.exe
C:\WINDOWS\system32\taskkill.exe "taskkill" /F /IM sqlservr.exe
C:\WINDOWS\system32\taskkill.exe "taskkill" /F /IM msmdsrv.exe
C:\WINDOWS\system32\taskkill.exe "taskkill" /F /IM Ssms.exe
C:\WINDOWS\system32\taskkill.exe "taskkill" /F /IM SQLAGENT.EXE
Show More
C:\WINDOWS\system32\taskkill.exe "taskkill" /F /IM ReportingServicesService.exe
C:\WINDOWS\system32\taskkill.exe "taskkill" /F /IM postgres.exe
C:\WINDOWS\system32\cmd.exe "cmd" /c "net start VSS"
C:\WINDOWS\system32\net.exe net start VSS
C:\WINDOWS\system32\cmd.exe "cmd" /c "vssadmin delete shadows /all /quiet"
C:\WINDOWS\system32\vssadmin.exe vssadmin delete shadows /all /quiet
c:\users\user\downloads\bfce02be8dc226e0336a4c53bbef0ccd9acb06ef_0001788416 "c:\users\user\downloads\bfce02be8dc226e0336a4c53bbef0ccd9acb06ef_0001788416" --target \\?\C:\
c:\users\user\downloads\bfce02be8dc226e0336a4c53bbef0ccd9acb06ef_0001788416 "c:\users\user\downloads\bfce02be8dc226e0336a4c53bbef0ccd9acb06ef_0001788416" --target \\?\D:\
c:\users\user\downloads\bfce02be8dc226e0336a4c53bbef0ccd9acb06ef_0001788416 "c:\users\user\downloads\bfce02be8dc226e0336a4c53bbef0ccd9acb06ef_0001788416" --target \\?\D:\
c:\users\user\downloads\bfce02be8dc226e0336a4c53bbef0ccd9acb06ef_0001788416 "c:\users\user\downloads\bfce02be8dc226e0336a4c53bbef0ccd9acb06ef_0001788416" --target \\?\W:\
c:\users\user\downloads\bfce02be8dc226e0336a4c53bbef0ccd9acb06ef_0001788416 "c:\users\user\downloads\bfce02be8dc226e0336a4c53bbef0ccd9acb06ef_0001788416" --target \\?\UNC\10.200.31.10\amas
c:\users\user\downloads\1b50330f094c688b947803cba4ee4dda08eb5fcf_0001788416 "c:\users\user\downloads\1b50330f094c688b947803cba4ee4dda08eb5fcf_0001788416" --target \\?\C:\
c:\users\user\downloads\1b50330f094c688b947803cba4ee4dda08eb5fcf_0001788416 "c:\users\user\downloads\1b50330f094c688b947803cba4ee4dda08eb5fcf_0001788416" --target \\?\D:\
c:\users\user\downloads\1b50330f094c688b947803cba4ee4dda08eb5fcf_0001788416 "c:\users\user\downloads\1b50330f094c688b947803cba4ee4dda08eb5fcf_0001788416" --target \\?\W:\