Threat Database Trojans Trojan.Lazy.BBL

Trojan.Lazy.BBL

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 27,730
Threat Level: 80 % (High)
Infected Computers: 2
First Seen: May 1, 2026
Last Seen: May 28, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Lazy.BBL
Signature status: Self Signed

Known Samples

MD5: 4d93a853bbc6f639bafef89a3fd53a0b
SHA1: 2d5c4d63aa6bba798c503b3e4c2fed1ebf0ad4e3
SHA256: F9223F8EDC098FDC1DEE957DA3F5490FA950F8303280D3A9D874D022281C4F68
File Size: 1.78 MB, 1775448 bytes
MD5: 0c9a09404c9a73dc01724be761aeea20
SHA1: e2bc34f7807732b95df5a53cfdbe0436ebd5a394
SHA256: F97A9603E4FAD3748E4D32CBA3265DA014221A4EE4C354295EA044E7ACD41A78
File Size: 1.77 MB, 1773928 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File has exports table
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Digital Signatures

Signer Root Status
Forge Technologies Sdn Bhd Forge Technologies Sdn Bhd Self Signed
Ranger Mechanics Sdn Bhd Ranger Mechanics Sdn Bhd Self Signed

File Traits

  • dll
  • x64

Block Information

Total Blocks: 643
Potentially Malicious Blocks: 115
Whitelisted Blocks: 525
Unknown Blocks: 3

Visual Map

x 0 x x 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 x 0 x 0 x x 0 x 0 0 x 0 x 0 x x x x 0 0 0 0 0 0 0 0 0 x 0 0 x x x x 0 0 0 x 0 0 x x x ? 0 ? x x 0 x x 0 0 x x x x 0 x x x x 0 x x 0 0 x x x x x x x x x x x 0 x 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x 0 x 0 x x x 0 x 0 x x x x x x x 0 x 0 x x 0 x x x x x 0 0 0 x x 0 x 0 x x 0 0 0 x x 0 x x x 0 x x x 0 x 0 x x x 0 x x 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 2 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Lazy.BBL

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
Show More
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile

Trending

Most Viewed

Loading...