Threat Database Backdoors Backdoor.Agent.TTD

Backdoor.Agent.TTD

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 10,337
Threat Level: 60 % (Medium)
Infected Computers: 10
First Seen: March 25, 2026
Last Seen: August 4, 2026
OS(es) Affected: Windows

The detection of Backdoor.Agent.TTD on your system indicates a potential security threat that requires immediate attention. This backdoor threat can compromise the security and integrity of your computer, allowing unauthorized access and potentially leading to further malicious activities. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Backdoor.Agent.TTD?

Backdoor.Agent.TTD is a type of backdoor threat that can provide unauthorized access to your computer, allowing attackers to remotely control your system, steal sensitive information, or use your computer as a botnet to conduct malicious activities. The term "backdoor" refers to a secret entrance or pathway that bypasses normal security mechanisms, allowing malicious actors to access your system without being detected.

How Backdoor.Agent.TTD Operates

Backdoor.Agent.TTD operates by exploiting vulnerabilities in your system or using social engineering tactics to trick you into installing the malware. Once installed, it can communicate with its command and control (C2) server to receive instructions and transmit stolen data. The malware can also spread to other systems through infected files, emails, or network connections. Its primary goal is to remain undetected, allowing the attackers to maintain access to your system for an extended period.

Symptoms of Infection

The symptoms of a Backdoor.Agent.TTD infection can be subtle, but some common indicators include unusual network activity, slow system performance, and unfamiliar programs or processes running in the background. You may also notice that your system is behaving erratically, or you are experiencing frequent crashes or freezes. However, in many cases, the infection may not exhibit any noticeable symptoms, making it challenging to detect without proper security software.

  • Unexplained changes to system settings or configuration
  • Appearance of unfamiliar icons, shortcuts, or programs
  • Increased network activity or unusual traffic patterns
  • System crashes, freezes, or slow performance

How to Remove Backdoor.Agent.TTD

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious components.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan to ensure that the malware has been completely removed.

Conclusion

Removing Backdoor.Agent.TTD from your system requires a combination of technical expertise and caution. It is essential to follow the removal steps carefully and use reputable security software to ensure that the malware is completely eliminated. After removal, it is crucial to take preventive measures to avoid future infections, such as keeping your operating system and software up-to-date, using strong passwords, and being cautious when opening emails or downloading files from unknown sources. By taking these steps, you can help protect your system and sensitive information from the risks associated with Backdoor.Agent.TTD and other malicious threats.

Analysis Report

General information

Family Name: Backdoor.Agent.TTD
Signature status: No Signature

Known Samples

MD5: c63d96a96ba8d575e4b094d3b806bb2e
SHA1: e915dcd67f351c4636752f77a5b082d5e128e24d
SHA256: 3E5F346CE4482257CCCDAEB54D7DDA5105067ADB29F119C5AB30DF560ECEBFAD
File Size: 7.15 MB, 7154176 bytes
MD5: 942d5af07d5f20a288a6f06e7c8a42a5
SHA1: 430c3ea362531b886bb584b2d07f828105f31a97
SHA256: C478BBE43876D0928619880CCB8A6D2E4A714119B08B71F12EBEA1A5057BA142
File Size: 1.27 MB, 1268736 bytes
MD5: 0a23d077f5a5efb693566daeebc4a360
SHA1: f0545eada0752e0a75f82c9c695674b4cdd4a000
SHA256: 637BDFC0FFCFE62B132257836C69BFA4AF7CC93A7CDD7684D01A1212F3976317
File Size: 4.84 MB, 4839424 bytes
MD5: 597c2b99dc57bd1665afa70c3986276a
SHA1: c0a1fa666128f719a86c0f2445d47d2a8b9bd3f9
SHA256: 2E4BC2B5B24D5F3A69E0D1A3E5DDA96D2FC5C69A8AA482063006B26EA2137C7E
File Size: 1.28 MB, 1276928 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • imgui
  • No Version Info
  • ntdll
  • VirtualQueryEx
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 2,033
Potentially Malicious Blocks: 557
Whitelisted Blocks: 1,440
Unknown Blocks: 36

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 ? ? x x x x x 0 x x x x x x 0 x x x x x x x x x x ? x x x x x x 0 x 0 x x x x x x x x x 0 ? x 0 x ? ? x x 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 x x x 1 0 x x 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 ? 0 x 0 0 x 0 0 0 x 0 0 1 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 x x 0 0 x x x x 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 0 0 x x x 0 0 x 0 x 1 x 0 0 x 0 x x x 0 x x x 0 0 0 0 x 0 x 0 0 x x x x x x 0 x 0 x 0 x 0 0 0 x 0 0 0 x 0 x 0 0 x x x 0 x x 1 0 x x x x 0 x x 0 x 0 0 0 x 0 0 x x 0 0 x 0 0 0 x x x x x x 0 0 0 0 0 x x 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 x x 0 x x x 0 0 x x x 0 x 0 x x 0 x 0 0 0 0 0 0 x 0 1 x 0 0 0 0 0 0 0 0 0 1 0 x 0 1 x 0 x x x 0 0 0 x 1 x 0 0 1 0 x x 0 x 0 0 0 0 x 0 0 0 x x 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 x x x 0 x x 0 x x x x x x 0 0 0 0 0 0 1 0 x x 0 x x x x 0 0 0 0 x 0 x 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 1 x 0 0 0 0 1 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 x x x x x 0 x x 0 x 0 0 x 0 0 x x x x 0 0 0 0 0 0 x x x x x x 0 0 x 0 x 0 0 1 0 x x 0 0 0 0 0 0 x 0 0 x 0 1 x 0 x x x 0 x 0 x 0 x 1 0 x x 0 1 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 0 x x 0 x 0 0 0 1 x x 0 x 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 x 0 0 1 0 0 1 0 0 0 1 0 0 1 0 0 1 0 0 1 0 0 1 0 0 1 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 x x x 0 0 x x 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 x 0 0 0 0 0 0 x 0 x 0 0 x x x 0 x x 0 0 x x x x x 0 x x x x 0 x 0 0 0 x 0 x x x x x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 x 0 x x 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 x x x 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 x 0 0 x 0 0 0 x x x 0 0 0 x 0 0 x x 0 x 0 x 0 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x x x 0 0 x x x x 0 0 0 0 x x 0 x x 0 0 x 0 x 0 x 0 0 0 0 x 0 x x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x x 0 0 0 x 0 0 x 0 x 0 x 0 0 0 0 0 0 0 x x x 0 0 0 x 0 0 x x 0 x x 0 x 0 x 0 x 0 x x x 0 x 0 x 0 x x x 0 x x 0 0 x 0 x 0 x 0 0 0 0 0 x 0 0 0 0 0 x x x x x 0 x 0 x 0 0 x 0 x x 0 0 0 0 0 0 0 0 x x 0 x 0 x x x 0 0 x 0 x x x 0 x x 0 x x 0 x x x x x x x x x x x x 0 0 0 x x 0 0 x 0 x 0 x 0 x 0 x x x x x x 0 x 0 0 x x 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 x x 0 x x 0 x 0 0 0 x 0 x x 0 0 0 x 1 x x x x 0 0 0 x x 0 x x ? 0 0 ? ? 0 ? ? ? 0 ? 0 0 x 0 0 x x 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x x x x 0 0 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 x 0 0 0 0 x x x x 0 0 0 0 x 0 ? x 0 x x x 0 x x x 0 x x x x x x x x ? x x x x ? x x ? ? ? x x x x 0 x x x x x ? ? ? ? 0 ? ? x ? x x x x x ? x x x x x 0 ? ? ? ? ? ? x x x x x ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 1 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN