Threat Database Backdoors Backdoor.Agent.TOE

Backdoor.Agent.TOE

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 9,714
Threat Level: 60 % (Medium)
Infected Computers: 13
First Seen: February 19, 2026
Last Seen: May 13, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Backdoor.Agent.TOE
Signature status: No Signature

Known Samples

MD5: 097201749ba775e74d8891baa64f9eec
SHA1: f503e1a07b84ebe520d0acd70b0e17b2e74f8aed
SHA256: 79E5E65A37FC3F369E2BA6911C3809C3A68A217DD69F395255A1B6AAC135EF14
File Size: 1.20 MB, 1201054 bytes
MD5: 5187e69ef351fa426a68bf30d7d04295
SHA1: 6a466fb723ebcb1d067c3de5ed8283e4162ed9fc
SHA256: 405A909290B9CA76F3905F98A345291F9DC86DC17EAC43209E41AAD50A542781
File Size: 1.19 MB, 1191708 bytes
MD5: 9355b94a0510cc10deb6445dbcb895eb
SHA1: 44d6df71ea96cc4375ef64433dd7c775338ebd40
SHA256: E2EDD37D6C5FD756C381ACD9ED784A09C0F90690C3646EC4E0C6EA40CF44A4F4
File Size: 1.18 MB, 1184014 bytes
MD5: a26e4ccd6b701f3de8be382e3c742b13
SHA1: 5c3c0e0c2b367bf4d8611a375b268954d09f5dd3
SHA256: A8B062DECB307699C3822845636164431791C1C7F108ACB78618D85714214222
File Size: 1.21 MB, 1208686 bytes
MD5: ccac9791a59b6875fa62609e6dbe185f
SHA1: 5b135967b050cedf0d8b7d7960681f0793041ac2
SHA256: 7CC54C87DA1010150962BC10A0D64A683E2BCE86BE2B7BBCC00172F3513BBB7E
File Size: 1.22 MB, 1223168 bytes
Show More
MD5: 59a76e6b8a2ea6f7c6b467466645cd06
SHA1: ce5e9b4bd73ce57d4d082b4fe7d1229972607f16
SHA256: 8663C3F056354B2A07FB65DA134A9B7BDF71CA79D2A494DD4D54D2A0B3BE8969
File Size: 1.21 MB, 1205930 bytes
MD5: e17daf8e5f744bc637f5209442ba493b
SHA1: 1667c8c191531d6851bcff223f418384892d0aa8
SHA256: B355D65B4D0A26EAC3C28F0F585CEF452FDF440939F7004DD13F09AE74A692E7
File Size: 1.20 MB, 1201852 bytes
MD5: d4ba40c942c6fe34a3bb0c03ba39468e
SHA1: 2a467d6cfc343064abcb058add62fdfc2f485f5f
SHA256: 3FE476E99154C458C05ADF390624372E03262937A11F9DD906DF0C85496023E1
File Size: 1.20 MB, 1196118 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • Block GmbH
  • Frequency Assets
  • International Channel Services
  • Lambda.port University
  • Lunar Nova Solid LP
  • Pure179 Broadcasting
  • Redquark Segment
  • Spiral Merge Society
File Description
  • Custom Smooth Record Index Helper
  • Frame Worker Platform Access Component
  • Inductance Asset Statistics Fetcher
  • Light Bargain Publishing Attach Helper
  • Red Attenuator Process Chunker
  • Resistance Process Payment Recorder
  • Suite Certificate Library Repair Program
  • Urgent Set Node Integration Gateway
File Version
  • 12.6.22.291
  • 11.3.3.88
  • 10.5.44.135
  • 9.4.79.126
  • 5.3.18.106
  • 4.3.81.235
  • 4.2.4.77
  • 3.5.58.311
Internal Name
  • channelupdater
  • document_include
  • eco_storage
  • keyfrconse
  • moderator_collaboration
  • offer_light
  • scriptprogram
  • ultra_command
Legal Copyright
  • (C) 2025 by Redquark Segment
  • (C) 2025-2025 International Channel Services. All rights reserved.
  • (C) 2026 by Lambda.port University
  • (C) Copyright 2019 Pure179 Broadcasting
  • (C) Copyright 2021 Block GmbH
  • (C) Copyright 2023 Spiral Merge Society
  • Copyright (C) 2013-2020 Frequency Assets
  • Copyright 2018, 2020 Lunar Nova Solid LP
Original Filename
  • channelupdater
  • document_include
  • eco_storage
  • keyfrconse
  • moderator_collaboration
  • offer_light
  • scriptprogram
  • ultra_command
Product Name
  • Backend Payment Debugger
  • Bandwidth Strategy Attacher
  • Bespoke Transform Request Forwarder
  • Clever Equalizer Initializer
  • Productive Pole Secondary
  • Silver Optical Agile Software
  • Vector Response Science Helper
  • WorkerInstaller
Product Version
  • 12.6.22.291
  • 12.0.12.127
  • 11.3.3.88
  • 10.5.44.135
  • 9.4.79.126
  • 8.6.3.399
  • 5.2.4.89
  • 3.5.58.311

File Traits

  • big overlay
  • fptable
  • Installer Version
  • ntdll
  • x64

Block Information

Total Blocks: 854
Potentially Malicious Blocks: 11
Whitelisted Blocks: 841
Unknown Blocks: 2

Visual Map

1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 ? 0 x 0 x 0 0 0 0 x x 0 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 2 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Trojan.Kryptik.Gen.EKR

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...