Trojan.Agent.BSA
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 4,132 |
| Threat Level: | 80 % (High) |
| Infected Computers: | 44 |
| First Seen: | April 2, 2026 |
| Last Seen: | July 25, 2026 |
| OS(es) Affected: | Windows |
The detection of Trojan.Agent.BSA on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operational characteristics, symptoms of infection, and most importantly, guidance on how to remove it from your system.
Table of Contents
What Is Trojan.Agent.BSA?
Trojan.Agent.BSA is identified as a Trojan-type threat. Trojans are malicious programs that can allow unauthorized access to your system, leading to a range of harmful activities including data theft, installation of additional malware, and disruption of system operation. The name "Trojan.Agent.BSA" itself does not specify a known malware family but indicates it is a type of Trojan agent, suggesting its capability to perform actions on behalf of its creators.
How Trojan.Agent.BSA Operates
Trojan agents like Trojan.Agent.BSA typically operate by disguising themselves as legitimate software. Once installed on a system, they can execute a variety of malicious actions. These may include stealing sensitive information such as login credentials, credit card numbers, and personal data. They can also create backdoors, allowing remote access to the infected system, which can then be used for further malicious activities such as spamming, spreading malware, or participating in botnet activities.
Symptoms of Infection
Symptoms of a Trojan infection can be subtle and may not always be immediately noticeable. However, common indicators include unusual system behavior such as slow performance, frequent crashes, and pop-ups. You might also notice unfamiliar programs or toolbars in your browser, or find that your browser's homepage has been changed without your consent. Additionally, if you notice that your system is connecting to the internet without your input, or if you are experiencing unusual network activity, these could be signs of a Trojan infection.
How to Remove Trojan.Agent.BSA
- Enter Safe Mode with Networking: This will limit the malware's ability to interfere with the removal process. Restart your computer and press the key to enter the boot menu (this key varies by manufacturer but is often F12, F2, or Del). Select the option to boot in Safe Mode with Networking.
- Perform a Full Scan: Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove Trojan.Agent.BSA and any other malware that may be present.
- Uninstall Suspicious Programs: Go through the list of installed programs on your computer and uninstall any that you do not recognize or that were installed around the time you noticed the infection.
- Reset Your Browser: If your browser has been affected, reset it to its default settings. This can usually be done through the browser's settings menu. For example, in Chrome, you can type "chrome://settings/resetBrowserSettings" in the address bar and follow the prompts. Similar options are available in Firefox and Edge.
- Reboot and Re-scan: After taking these steps, reboot your computer and perform another scan with your anti-malware tool to ensure that the threat has been fully removed.
Conclusion
Removing Trojan.Agent.BSA from your system requires careful and methodical steps to ensure that all components of the malware are eliminated. It's crucial to stay vigilant and keep your security software up to date to prevent future infections. Regularly backing up important data and being cautious when opening email attachments or downloading software from the internet can also help protect your system from malware threats. If you are unsure about any part of the removal process, consider seeking help from a professional to ensure your system is thoroughly cleaned and secured.
Analysis Report
General information
| Family Name: | Trojan.Agent.BSA |
|---|---|
| Signature status: | Self Signed |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
1ff46df0012bec84e05e4b370f22fd6a
SHA1:
4ee5c9e78ddf5f80fc476d2e66645393079769a8
SHA256:
A9CC7EE52A96651D7CC7AC0ED3550A2130B23B47CD1983A3C19474B16F1C785D
File Size:
2.28 MB, 2278672 bytes
|
|
MD5:
940ac87ce602e347ad5ba202567d3a20
SHA1:
173824fdc3a534f7c54155c3bdd91114a74e5600
SHA256:
F018582A248D3BA59778AB84CDBCC50F74D1F9570633D3843848ABAB094FF937
File Size:
2.26 MB, 2263264 bytes
|
|
MD5:
10bc794eae971ae96739dcaa7a40f641
SHA1:
1b344d6922c272b9189517296d86a28d7b4abb35
SHA256:
598FBC232FE94ADC1F11BF37C14F9A570BBF2546CB383BA85AD434E18672242E
File Size:
2.31 MB, 2305256 bytes
|
|
MD5:
b1a4ec7b14f0de1e9d3e8b21bf6e1e61
SHA1:
c0a3aec7f7a8d3b4c415b39b277d34d8c21c49bd
SHA256:
86ECA405D962C54CD20F6BB6217EC0BD4FDFD973814AD294E1EFE36D2A8418C0
File Size:
1.57 MB, 1565824 bytes
|
|
MD5:
fc56cbd1c795ee65869dd465c83d9523
SHA1:
5055036dc0a3588c99f53fa160cd803609a68453
SHA256:
16A8F92653EA8838CE2FA376CAE48F3F448E7AC95758AFA23C0AC1E808A78F89
File Size:
4.88 MB, 4881032 bytes
|
Show More
|
MD5:
7c4aa03cf7b51023cf28780982adef34
SHA1:
7318901f0a94c5cdca585578105adf6c0e6f56be
SHA256:
675E44C5BB90529266748DF7D189D75B8AFFBDF2ABE19327AD1395B27BD66FE6
File Size:
2.34 MB, 2339456 bytes
|
|
MD5:
339b9f286183badf8fa4c35d25adb22b
SHA1:
e84708da5a7e97fd05a4ddf1c9f6047f6c2f66a8
SHA256:
3AC1FF971999667424BFCF977F013610CAA421E4FECE459FB872BF376778D1E5
File Size:
2.07 MB, 2065320 bytes
|
|
MD5:
684c162c7b289a954cd7b4ab4d94d213
SHA1:
2cec4197fd77711e3d346c50307d155da3f0079b
SHA256:
F941E349CCB4F8300D6C1004CF4F716304BD8963D989ABE853E4CF6B861941AC
File Size:
3.43 MB, 3432296 bytes
|
|
MD5:
18c096e270f48417aadc12d9d4ed80a3
SHA1:
a5569e031eec1a3877609629e61e513c50e00716
SHA256:
E24A6ABFB966128BCFF34A9E9119788D6109BEE653C97F22E1139C29E624CEDA
File Size:
3.93 MB, 3925824 bytes
|
|
MD5:
4c91bfc7105f6170952e3e3739f7859d
SHA1:
6bdb9ab6f72e95fc6d217901fa16c63c6eba0467
SHA256:
89F3D018B8B0D5C789F3F72911BD91D3D6286D46AA73CDDD7FE7FBB63F06BBE7
File Size:
3.59 MB, 3593856 bytes
|
|
MD5:
2553682a50b163029e9538a31f518107
SHA1:
15c1f23886f9d4031239a93a892291a22ee374eb
SHA256:
21317C7329C6B32F215F6C7C0A71B0B79F00150F5522F8D63E524AEA746A79BF
File Size:
3.70 MB, 3700608 bytes
|
|
MD5:
f59116de561a71ae89993d4c0b72fdd5
SHA1:
1632ea5c084ad40313dd34248b296092ca322cbe
SHA256:
364C29657F6B99BBBC641CC7DA5CBAC30DA211DD96EEBF19B41A18417BD13321
File Size:
4.40 MB, 4395392 bytes
|
|
MD5:
68d09c8d736f0ef0a80436ead7d8dc42
SHA1:
34f2e877d8e7e7eeecc175727815e2f1873a2757
SHA256:
8726290C52CF50BCA6D6ABA7D95ECC0F7E7CE809B2E26A88F1D8AE82A1E38C7D
File Size:
2.62 MB, 2618736 bytes
|
|
MD5:
c932d4c3f54e3902d57abff3c58e09b6
SHA1:
19c9e3a374e5402b52bc8402768c73b6397cf4f1
SHA256:
A64E0733553C506A1E0785F0BCA26406ABC3CE0C4256697E377A1B967BE36677
File Size:
3.47 MB, 3471736 bytes
|
|
MD5:
a55f7b2226c1d9dbd94fe0a9d385473c
SHA1:
4b0fe8285d999cea08709495d598ca7c9d7a656e
SHA256:
9FD59B56EA2C757EE6F2B8FDDC45F7D36EFECA135CEE1C92511799C85351EBF3
File Size:
2.96 MB, 2958200 bytes
|
|
MD5:
14e32bb37f2b7bd9451ac5733807082d
SHA1:
ffc13ca23ae80a3ddbbd478de01a75cf087f105c
SHA256:
EB9E2BA2CED273E4D2C3D3FCE4848FAACABA0A0F76110FE8425089DD07B301F8
File Size:
2.92 MB, 2924920 bytes
|
|
MD5:
17c783bb84f17edb43a538f0dfbeb1e9
SHA1:
d906cde072f34edb752b66a097b8284300b88a3b
SHA256:
79A00DC593777F03F4DE27E234F44908A91D600766F34B40F59AA2100000DD09
File Size:
2.89 MB, 2889112 bytes
|
|
MD5:
2c47a6ee4a06d520bfbbde8ee14b2625
SHA1:
719aaa5191a5a26ac1de2e636a707b874d0c78d9
SHA256:
DCC615F76E648650B71FE287E3691F7EF035386B03D596E40049841B3BE4A450
File Size:
3.47 MB, 3468160 bytes
|
|
MD5:
d9cea73eff44fe6716c6b794a3ccfd2f
SHA1:
decc2506c1a205ee091ba41b55fb3c84cb848dba
SHA256:
A8F4E570BBFF9B262B91EA8F89EC7C7D8B2AC9B6C435004446E9A79F0E272664
File Size:
4.40 MB, 4401128 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have resources
- File has exports table
- File has TLS information
- File is 64-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
Show More
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Digital Signatures
Digital Signatures
This section lists digital signatures that are attached to samples within this family. When analyzing and verifying digital signatures, it is important to confirm that the signature’s root authority is a well-known and trustworthy entity and that the status of the signature is good. Malware is often signed with non-trustworthy “Self Signed” digital signatures (which can be easily created by a malware author with no verification). Malware may also be signed by legitimate signatures that have an invalid status, and by signatures from questionable root authorities with fake or misleading “Signer” names.| Signer | Root | Status |
|---|---|---|
| 1575d9b8.sni.cloudflaressl.com | 1575d9b8.sni.cloudflaressl.com | Self Signed |
| autoz.com.br | autoz.com.br | Self Signed |
| beebom.com | beebom.com | Self Signed |
| computrabajo.com | computrabajo.com | Self Signed |
| cryptomus.com | cryptomus.com | Self Signed |
Show More
| luxurylink.com | luxurylink.com | Self Signed |
| tycsports.com | tycsports.com | Self Signed |
| vm.bit.hosting | vm.bit.hosting | Self Signed |
| www-cs-02.oracle.com | www-cs-02.oracle.com | Self Signed |
| www.lojadomecanico.com.br | www.lojadomecanico.com.br | Self Signed |
| www.pakistani.org | www.pakistani.org | Self Signed |
| www.rebelsport.co | www.rebelsport.co | Self Signed |
File Traits
- big overlay
- dll
- golang
- HighEntropy
- No Version Info
- x64
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 8,853 |
|---|---|
| Potentially Malicious Blocks: | 7 |
| Whitelisted Blocks: | 6,159 |
| Unknown Blocks: | 2,687 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Adaptix.B
- Agent.BSA
- Agent.GFG
- Agent.JFJ
- Agent.KTSE
Show More
- Agent.MPF
- Agent.MPZ
- Agent.MYS
- BadJoke.KGB
- CoinStealer.CC
- Dropper.BFA
- Dropper.PPA
- Kryptik.BFSC
- Kryptik.BFSM
- Kryptik.BTE
- Kryptik.ERA
- Kryptik.FRS
- Kryptik.FRSA
- Kryptik.FRSD
- Kryptik.GDSY
- Kryptik.GOA
- Kryptik.MFRA
- Kryptik.MFRB
- Kryptik.MHD
- Kryptik.MHE
- Kryptik.VDH
- Kryptik.VY
- MSIL.Brute.TT
- Quasar.TBA
- Rozena.ED
- Rozena.MC
- ShellcodeRunner.LWA
- ShellcodeRunner.RDB
- SmokeLoader.E
- Trojan.Agent.Gen.BWC
- Trojan.ShellcodeRunner.Gen.FZ
- Trojan.ShellcodeRunner.Gen.KT
- Trojan.ShellcodeRunner.Gen.LZ
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �m �� �v����(�*�"1�1HO @V� H[u_�zb"hc�w k�qw�n{b��P� ����� ��� ������ ��m� Ù� �V ����$�8წ�� �=�S) � B1_ T�Vw��`� ��%������ �AE��"��D��&��$���L A *�" | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | n �v��Bx (�1�1HO @V� _�zb"hi��rnJ u�~ {b��P� ������ ������m� Ù� �� ����$წ����o ��=�SB1_ T�Vw�`�V�R� ��%������ �AE�Q] ��D��&��$���L | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
|
| Network Winhttp |
|