Threat Database Trojans Trojan.Downloader.Agent.BBC

Trojan.Downloader.Agent.BBC

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 10,958
Threat Level: 80 % (High)
Infected Computers: 1,695
First Seen: August 10, 2021
Last Seen: March 4, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Downloader.Agent.BBC
Signature status: No Signature

Known Samples

MD5: c655f26aeed8ddfa9c5b8775fd253184
SHA1: b1e2b609d85c83bcf35b27ed0f85f14cd15872f6
SHA256: F89CEFD1238CF39606251589BB733B9E075B7D845BC222CB1A5304900A880C6E
File Size: 3.76 MB, 3763043 bytes
MD5: ef6e248b977a66c74d7171ecba7dadaa
SHA1: 27d17f5a99815ce916350397e7417f288b1e7375
SHA256: A0C45FACFAB14C7A4BF3E20DD9C3EDD91CA4E6D7E2BE98BA88CD577ED5323B61
File Size: 460.29 KB, 460288 bytes
MD5: e09d21346f5fa55f2da8a0cae74f9bef
SHA1: 3f460dec679d9c50967addd759c0ec3b5e538a39
SHA256: 492A97E1C4C513F8DA8B7E62FACAA6A522F9AC0C23ED21EE92A3EFD0611F8119
File Size: 684.24 KB, 684235 bytes
MD5: f07d36a597c2ba2fff94a49d101409c6
SHA1: 61acbf4c4524c9347a82a1f592937b4cca163e73
SHA256: 068DD8FBC254C2C27FF29B9E3CBF95A2380B52D0243482767E71A433DA41EAE2
File Size: 8.88 MB, 8878886 bytes
MD5: c8d23975f1d9227f4ab9f7bc34a2b7df
SHA1: 5d1c5a72fbf34ea5dd14b580460d0c39f8870836
SHA256: 27B15AE9AA8E55A5C56BD60B2BC20F3C2C077BB4B15380F5F2BB46A43F874252
File Size: 1.69 MB, 1690112 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Microsoft Corporation
File Description
  • Microsoft Setup Bootstrapper
File Version
  • 12.0.4518.1014
  • 1.00
  • 1.0.0.0
Internal Name
  • setup.exe
  • TJprojMain
Legal Copyright
  • © 2006 Microsoft Corporation. All rights reserved.
  • © 2006 Microsoft Corporation. All rights reserved.
Legal Trademarks1 Microsoft® is a registered trademark of Microsoft Corporation.
Legal Trademarks2 Windows® is a registered trademark of Microsoft Corporation.
Original File Name setup.exe
Original Filename
  • setup.exe
  • TJprojMain.exe
Product Name
  • Microsoft Setup Bootstrapper
  • Project1
Product Version
  • 12.0.4518.1014
  • 1.00
  • 1.0.0.0

File Traits

  • 2+ executable sections
  • HighEntropy
  • Installer Manifest
  • Installer Version
  • x86

Block Information

Total Blocks: 2,108
Potentially Malicious Blocks: 407
Whitelisted Blocks: 1,701
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 x x x x x 0 x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 x x x x 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 x 0 0 x x x x x x 0 0 0 0 x 0 0 0 x 0 0 x x 0 x x 0 0 0 0 x 1 0 0 x x x x 0 x x x x x 0 x x 0 0 x x x x x x x x x 0 0 0 0 x x x 0 0 0 0 x 0 x x x 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x 0 0 x 0 0 0 x 0 0 0 0 x x x x 0 x x x x 0 0 0 x x 0 x x x x x x x x x 0 x x x 0 x x 0 x x x x 0 0 0 x x x x x x x x x 0 0 0 0 x 0 x 0 0 1 0 0 0 0 x 0 0 0 0 x 0 x 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 x 0 x 0 x x x x 0 0 0 x 1 0 x 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 1 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 x x 0 0 x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 1 x 0 x x 0 0 0 0 0 x 0 x 0 x x 0 1 x 0 0 0 0 0 x 0 0 x 0 0 0 0 0 x 0 0 0 x 0 0 0 0 x 1 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 x x 0 x 0 0 x 0 1 x x x 0 0 x x x x x 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 x x 0 0 x 0 x x x x 0 x x 0 x 0 0 0 x x x 0 1 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 x x x 0 0 0 x 2 0 0 3 1 0 x 3 0 0 0 0 0 0 x x x x x x x 0 0 0 1 0 0 0 0 0 1 0 0 0 x x x x 0 0 x x 0 0 0 0 0 0 x 0 0 x x 0 x 0 x 0 x x x x x 0 0 x 0 x x x x x x x 0 x x x x 0 0 x 0 x 0 0 0 0 0 0 0 x 0 x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x 0 x 0 x 0 0 x x x 0 0 x x 0 x 0 x x 0 x x 0 x x x x x x x 0 x x 0 x 0 x x 0 0 0 x 0 0 x x 0 x x 0 x x 0 0 0 0 0 0 x 0 x 0 x x 0 0 1 0 x x x x x x 0 0 0 0 x x x x x x 0 x x x 0 x 0 x 0 x 0 x x x x x x x x x x 0 x x 0 x 0 x x x 0 0 0 x x x x x x 0 0 0 x x x 0 x x x x x x x x x x x x x x x x 0 x x 1 0 1 1 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 x 0 x 0 0 x 0 x x 0 x 0 x x x x x x 0 0 0 x 1 0 0 0 x 0 0 x 0 0 0 0 0 0 x 1 1 x 0 0 x 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 1 1 0 0 x 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 1 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 x 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 1 0 1 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 1 1 1 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Bancteian.B
  • Banker.FD
  • Downloader.Agent.BBC

Files Modified

File Attributes
\device\namedpipe\toserveradvinst_extract_c:\users\user\downloads\61acbf4c4524c9347a82a1f592937b4cca163e73_0008878886 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\icsys.ico.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\setupexe(202511062220501658).log Generic Write,Read Attributes
c:\users\user\appdata\local\temp\setupexe(20251127141648ae8).log Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\direct x 13.0.2.4\install\teste.msi Generic Write,Read Attributes
c:\users\user\downloads\b1e2b609d85c83bcf35b27ed0f85f14cd15872f6_0003763043  Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\b1e2b609d85c83bcf35b27ed0f85f14cd15872f6_0003763043  Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows\currentversion\policies\system::consentpromptbehavioradmin RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\policies\system::enablelua RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\policies\system::promptonsecuredesktop RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerName
  • GetUserName
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • WinExec
Other Suspicious
  • SetWindowsHookEx
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
  • OutputDebugString

Shell Command Execution

c:\users\user\downloads\b1e2b609d85c83bcf35b27ed0f85f14cd15872f6_0003763043�

Trending

Most Viewed

Loading...