Trojan.Agent.AVBB
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 445 |
| Threat Level: | 80 % (High) |
| Infected Computers: | 7,111 |
| First Seen: | April 22, 2023 |
| Last Seen: | April 19, 2026 |
| OS(es) Affected: | Windows |
Table of Contents
Analysis Report
General information
| Family Name: | Trojan.Agent.AVBB |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
88c21db27c5044bd5e8084da1eefec03
SHA1:
9f9562f0326daa06646a782f0e5ec017441c9339
File Size:
256.07 KB, 256072 bytes
|
|
MD5:
594ca013673f414967af5191eb84d0fc
SHA1:
7de2a776c8f9483ffadd19a6dd1fc8278974532e
SHA256:
EA43FB3B1CBEFFFB26BBFAFC6B1E856E5A0626556EEAE1DF5356A392AA95C2D4
File Size:
256.07 KB, 256072 bytes
|
|
MD5:
1e1c51fbc890d9a87020e19000d64fc1
SHA1:
eaa2d4af802a6e9b32aec115fc3b6e027f5eaa3f
SHA256:
3F75A5E373991AE4C1253156861CDBD44577C8F1C9B5382D730BEF8C1F6791D8
File Size:
248.96 KB, 248960 bytes
|
|
MD5:
00b2c3200e128b28c80d34b8ee9af811
SHA1:
27bfbded27b02705ff96b77d3437872efb711ff3
SHA256:
C30B79088BC74B0BACF8FDE1D81F7489F16CA1B427C5814EEA75F621983EAD6A
File Size:
249.47 KB, 249472 bytes
|
|
MD5:
598f6664e2b18ecd19563e7b946356f8
SHA1:
df7547e8b8c4e3e27e91096ddd7a5ebe93876adf
SHA256:
9FB61282E66600CE4F1BEED3CAE03521034AF842065B7DAA3F22E6C9E8CA20D3
File Size:
243.78 KB, 243784 bytes
|
Show More
|
MD5:
7328ad11e27172273321075f0cf1f654
SHA1:
063092b05f0fc9d9595cbd7a9e92691f4ca953a1
SHA256:
3C84A0857E8DD84C752F5491C23762E0138D07202B8EEC03FD53F8820ECE1CE3
File Size:
251.48 KB, 251480 bytes
|
|
MD5:
528da411a62c20367ecc2146e3f5e30b
SHA1:
2d0db1f09be3d10782247954cd2c2cd556eebf79
SHA256:
898BC2DB6FA0165D8AE708A5CF64B01F936467CFA0611D91A950800363F6DD91
File Size:
248.96 KB, 248960 bytes
|
|
MD5:
1244153240a4bdc92b7c80ff7f687214
SHA1:
0b66aba021d44bd28cf46945d7f5489d8057e1b4
SHA256:
554538305A30F949CE90E72706DBA291D5BA0DF20746AFA61B711E7CFD6268BE
File Size:
248.96 KB, 248960 bytes
|
|
MD5:
2cd71ebb3ca30a71ac8af3a28fddb0a2
SHA1:
ac7b6c3a43dd6394f949e9a3d07be682a250c574
SHA256:
1066A5B1FC8150C5551AE977100764D960501E197EC5CE7A8E2EF92A5EA97A59
File Size:
251.48 KB, 251480 bytes
|
|
MD5:
789800d3797d40016144e0cb1eeb4587
SHA1:
8edbc066683bbe5e26afeabf06be80506e6f16f8
SHA256:
89A97C7B2531FA689299D154D225B306949D18489B6EC112187755E254199708
File Size:
249.47 KB, 249472 bytes
|
|
MD5:
6ace5bbd1ab0910f49e8e08416acb72a
SHA1:
9a022a2e2f04e2a212ec2bbd89c0fcde60d80d58
SHA256:
BC57D6C3B9FB36ACBE72475B24C6B2BBE0A3238C087EE32549028A66AF175095
File Size:
251.48 KB, 251480 bytes
|
|
MD5:
62651f1fe064aa0b71a0e93565b21cad
SHA1:
15c34346e8a5a112fcf3ab284198a9281a88a5c6
SHA256:
FCC96AC056394793B253A03E6E768E6963365DA542E056C06AA3144AE957AD7A
File Size:
247.38 KB, 247376 bytes
|
|
MD5:
11075de3cc3c8601b4d1e27504c7207f
SHA1:
266ade8e0d170acd45633846e1652270a2d95604
SHA256:
19F8F4A79DB3BA23A169B04CFD24633F9194DAF1D76E4E7528F8914CAEBA346C
File Size:
251.48 KB, 251480 bytes
|
|
MD5:
54880109c5092867edd8254e2cf9c11d
SHA1:
861bad79f7e093fd069e62ea31593d7d0a8e4d88
SHA256:
A38A4D439AC84C0F906CA06368D630B0B2FC7CB0DF178D1D026506DD1967105A
File Size:
247.38 KB, 247376 bytes
|
|
MD5:
5beb2cdad1eadf2ce807fff2313d01a8
SHA1:
3e5e337256097b737c8bf8ac7f99971932ea41a2
SHA256:
1585252934CD1BDE5E8768786C44CCE9F26B698D46F12D40A4B7EB236C77ACDF
File Size:
251.49 KB, 251488 bytes
|
|
MD5:
8e95ec03375374a16c989bb3591327ad
SHA1:
9ee34f0567ff87eb28f9311c7ad222239ee0e5df
SHA256:
C73430BDD8288614FA82235CAC99EAF686F399D013D5E96B3A593AD94BC9D0E3
File Size:
251.48 KB, 251480 bytes
|
|
MD5:
eb1eba1ed3f2bc5069e468cf90750dd9
SHA1:
40e2a49c3eecb8f553884cc51ff72b46e5cb9032
SHA256:
A72C348452B2621C2260A45DD7DF9495A2CB353DE0165F6AD0654D9BDB78081B
File Size:
252.49 KB, 252488 bytes
|
|
MD5:
5a692744b01a9d84ea460ea58dffa206
SHA1:
43636d0225fb13f2bcaad26a21e650bd3da78210
SHA256:
22327A7BA22A1972276C46C8D48DF249A3C67F75DD514352A687FDF472197907
File Size:
247.40 KB, 247400 bytes
|
|
MD5:
ce89accd82de5ea53082259067acb0ce
SHA1:
0c1d6e6641511ef95346515d6bee361ce75c8954
SHA256:
187F04A0B048D607D46F7D575E5A662852DAFEE9B70ECE91F8FC65CDFEAFCDED
File Size:
251.98 KB, 251976 bytes
|
|
MD5:
71d4f6cf0d952fa947329624d1d8200b
SHA1:
bf63c91b9f682b5606977890801526b0fc525fb4
SHA256:
E94E2D91787A8D1711FB3422EBFF8793BD27097BFDC577CE0DB4703BDD3DE634
File Size:
239.89 KB, 239888 bytes
|
|
MD5:
4b1aadbad1b0c7104e2f3d8cf77b283b
SHA1:
4644c2560f4d1018270c7f20ecbd157b81b80236
SHA256:
C70A835068BCA91525342D31774730F1214C9041AADAC8EAE342143B7C0DA48D
File Size:
249.47 KB, 249472 bytes
|
|
MD5:
da56f4c90b218fe84eb299c4a9edd1ae
SHA1:
57749cff792a9fa2a5fe7619698661c17035c958
SHA256:
10C1B5DED0CF182E16820B5EB2947FE4A3854784AF4DEDE449EBB64BA0077C2D
File Size:
239.93 KB, 239928 bytes
|
|
MD5:
c94dd87adf9e1115e6c20e5256870cd2
SHA1:
5d8a32f3ad4fec571ca765e03f0bd5003c9b46d8
SHA256:
74CEE94634CC50A53792B03CF83FCBB41D630D08D9B49CD2A2D52E6AD888C022
File Size:
239.93 KB, 239928 bytes
|
|
MD5:
fca53503041bdfdff495c081f3b032cf
SHA1:
742283bf52985bd99572c7c54b662617d2bdef1f
SHA256:
021645D070DBC1854B9B3B99D49D60F46C19486C98262E04D65D5DC318A90595
File Size:
259.32 KB, 259320 bytes
|
|
MD5:
d23d9fd8d18203c4cff843c892414cc6
SHA1:
6ea61bd6851c7d0b9c396ac4f6b0c4ee0b49b146
SHA256:
92A7D7F14F31749226C992BF17EE4D8B665BEA0423A304C245955CAFFD19A50F
File Size:
244.30 KB, 244296 bytes
|
|
MD5:
119f812c1746505b233de49892b427ea
SHA1:
02640b2dd7e3fa52e6c55647989341d6cba5f916
SHA256:
4B20044672D1B69B9C12062F19B879EBBF3E75C85D3C1756FFAE078CDF95EC3F
File Size:
239.89 KB, 239888 bytes
|
|
MD5:
c93b1bbd62ece1fe5d98d39f3049340c
SHA1:
0ec14f3c99db24b4a70ef84f131af92a6c8ebdd6
SHA256:
D5CF0C678975C9C5F89FDB8B314AF62CBE96788DF8F8C97088EC10F1848D1935
File Size:
239.89 KB, 239888 bytes
|
|
MD5:
334ec3667fd8c6cc112957eb91ff5e09
SHA1:
7257286a1d3f5a4d468792151067c4468cd623c4
SHA256:
204E256F51BC6BF59C529F3815B3EEFAAA650BA634D69CC904EBB591FDAC9CEF
File Size:
239.86 KB, 239864 bytes
|
|
MD5:
6075dde9191fb44e324aae33164ad9be
SHA1:
183ba3cb5fdbc41b9bcf6aac57e7f14f6ad390af
SHA256:
1A326E17B32AAEAB4D47D1DB469A3D49FE6DC0195E19242FC44887AB05E88C4D
File Size:
239.86 KB, 239864 bytes
|
|
MD5:
1c2038ba7039beecf067f576d9257b15
SHA1:
1eb17a427de9f203c0aa190f7b363286ff50cbc0
SHA256:
1B4E595E7F151420E54432FD44AD579258E5FD145AF3E6776977CCEBB85BF693
File Size:
239.86 KB, 239864 bytes
|
|
MD5:
00aa033755fb4465696d589d27b96024
SHA1:
154cf621d523429d6ef490b432a3624017f67383
SHA256:
E0F2CB84302ECE8B7F36B81A977DD3016F6C4648A6C6DBEAD3B9C3535E324A20
File Size:
259.86 KB, 259856 bytes
|
|
MD5:
6d0f67faa41b49d5ae103ce85d5f16ef
SHA1:
75cdbf1ad9a058c1290a7128f131fd40075835e3
SHA256:
35EAD40C0EA3B5A31386E7C41CC6D945633B82751F9773DB52E8248A81789E8C
File Size:
259.86 KB, 259856 bytes
|
|
MD5:
8b1439183e9e5875cfede606dcd04dd5
SHA1:
0f5613109b762d3d7897b3ded4582c8d5f11597b
SHA256:
7AB9A7BA0A19D3183C08BD338EB1E67C6F208801DDC14AAC4E0947BC2E4D9BCA
File Size:
247.38 KB, 247376 bytes
|
|
MD5:
d8763e0c591b9ed68f0e853c3e8be6bd
SHA1:
1125c7179db7f45f079a47ef00e947e512594a4a
SHA256:
4C17D14306763AA8CAF0C74BC56E771C81EEBE6368A2B5E38F33DF4DD1F8C88C
File Size:
239.93 KB, 239928 bytes
|
|
MD5:
9ec104bf9dfaf969dc359a97ea63c927
SHA1:
cf77d82b71f4b920f65da6dd5c915d4bed73bc93
SHA256:
8359037530F2B04AA5D00A3662550BC2EA58DFDC6173C2F35768E3903159B9B8
File Size:
239.93 KB, 239928 bytes
|
|
MD5:
07200ecb75a2a5c4a737985299aca79a
SHA1:
751e2d4f7d19bfb76fcb2563401ae20214f84d36
SHA256:
68C807D7BD6E2DAA26EF7EB97C9C13A582ADC3E04D96D6D47141C38B9D286EC4
File Size:
239.90 KB, 239904 bytes
|
|
MD5:
85446a85194e207c3c431e39d937e25c
SHA1:
cf927b7b71d65d68ff77f34d63a45d81469f9f59
SHA256:
20511A76EC073865E8792B15B88720575C1389377D61AAEE30FA5BC065F79CF8
File Size:
239.90 KB, 239904 bytes
|
|
MD5:
77ee8cda40686f92f4ef5ef5c3420f46
SHA1:
bdad5d2ce0bc6bef41eb721fef9e7a6b6f4b64a0
SHA256:
F78BDBD94E06CDB0F3FE53EE518855E88A9B50BEBD171404DAE91A3B2125DC95
File Size:
239.90 KB, 239904 bytes
|
|
MD5:
8b988043f96f0f5dd3fd02788052cbf1
SHA1:
2cc9f80b15c96b6d47709610b6776d29163099c3
SHA256:
5F79B40DB39DC3E1223C0FFB76848E1600888C8AC7F7477B64D40868A42BA2EF
File Size:
239.90 KB, 239904 bytes
|
|
MD5:
090a8f046a20a191ad651a79cdaf4dd3
SHA1:
bbb7b2e89b9a951017a6ab6c44ff8b16c9ce9307
SHA256:
535AC81B303F56AE50A5E02B31550103061CBF0C4598D06B863A32D6F8498A83
File Size:
239.90 KB, 239904 bytes
|
|
MD5:
cb0249504f5012a91e7be4c18aa7ce25
SHA1:
c73fb7b73fb9b2048c9fcf3ede9415099fd92086
SHA256:
2D8172AA41726A62092CEBAE095E7982B124E0055ABF46BF467BE2B1CEB4C885
File Size:
239.90 KB, 239904 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have security information
- File has exports table
- File has TLS information
- File is 64-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| File Description |
Show More
|
| File Version |
Show More
|
| Internal Name |
Show More
|
| Product Version |
Show More
|
Digital Signatures
Digital Signatures
This section lists digital signatures that are attached to samples within this family. When analyzing and verifying digital signatures, it is important to confirm that the signature’s root authority is a well-known and trustworthy entity and that the status of the signature is good. Malware is often signed with non-trustworthy “Self Signed” digital signatures (which can be easily created by a malware author with no verification). Malware may also be signed by legitimate signatures that have an invalid status, and by signatures from questionable root authorities with fake or misleading “Signer” names.| Signer | Root | Status |
|---|---|---|
| Turn Urge | Affair Will | Self Signed |
| AlYDev Soft T | AlYDev Soft T | Self Signed |
| AlucSoftVB Dev | AlucSoftVB Dev | Self Signed |
| AtrcDev Group B | AtrcDev Group B | Self Signed |
| AtrcDev Group V | AtrcDev Group V | Self Signed |
Show More
| AtructisDev Team M | AtructisDev Team M | Self Signed |
| Inferior East | Clench Mankind | Self Signed |
| Whereas Attorney | Dazzle Cushion | Self Signed |
| DioPakoSigner | DioPakoSigner | Self Signed |
| Loud Dawn | Fringe Plumbing | Self Signed |
| Make Vent | Quite Exuberant | Self Signed |
| Adopt Send | Reluctant Jury | Self Signed |
| Footprint Merit | Wallpaper Mug | Self Signed |
File Traits
- dll
- x64
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 697 |
|---|---|
| Potentially Malicious Blocks: | 32 |
| Whitelisted Blocks: | 616 |
| Unknown Blocks: | 49 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Agent.AVBE
- Agent.KOM
- Agent.UFSI
- Emotet.ABI
- QQPass.LC
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
4 additional items are not displayed above. |