Threat Database Backdoors Backdoor.PSW.Agent.KFC

Backdoor.PSW.Agent.KFC

Backdoor.PSW.Agent.KFC is a malicious program classified as a backdoor with password-stealing (PSW) capabilities. Threats in this family are designed to give attackers unauthorized remote access to an infected computer while also harvesting sensitive credentials stored or entered on the system. Because specific technical details about this particular variant are not publicly documented, this article describes the typical behavior associated with backdoors and password-stealing trojans in this category so users understand the general risks involved.

What Backdoor.PSW.Agent.KFC Typically Does

As a backdoor, this type of threat is built to open a hidden channel of communication between the infected machine and a remote attacker. Once active, it can allow cybercriminals to execute commands, upload or download files, install additional malware, and monitor activity on the compromised system without the user's knowledge. The "PSW" designation indicates that the malware also attempts to locate and steal passwords and other credentials, which may include login details for email accounts, online banking, social media, or other sensitive services stored in browsers or applications on the device.

Typically, backdoors of this kind run silently in the background, avoiding obvious symptoms so they can continue operating undetected for as long as possible. They may also disable or interfere with security tools, modify system settings, or establish persistence mechanisms so they automatically restart when the computer is rebooted.

How It Usually Gets Onto Computers

Backdoor and password-stealing threats commonly spread through deceptive methods rather than exploiting a single specific vulnerability. Typical infection vectors include malicious email attachments, fake software downloads, cracked or pirated program installers, infected removable drives, and links embedded in phishing messages. Users may also be tricked into downloading the malware disguised as a legitimate update, game, utility, or document. In many cases, victims unknowingly install the threat themselves by running a file that appears harmless.

Risks for the User

The presence of a backdoor combined with password-stealing functionality poses serious risks. Potential consequences include:

  • Unauthorized remote access to the computer by cybercriminals
  • Theft of login credentials, financial information, or personal data
  • Installation of additional malware, such as ransomware or spyware
  • Use of the infected machine as part of a larger network of compromised computers
  • Loss of privacy, identity theft, or financial fraud

Signs of Infection

Because backdoors are designed to remain hidden, signs of infection are not always obvious. However, typical warning signs that may indicate a compromised system include unexplained slowdowns, unusual network activity, programs opening or closing on their own, new or unfamiliar processes running in the background, changes to browser or system settings without user action, and security software being disabled unexpectedly. Users may also notice unauthorized logins or suspicious activity on their online accounts.

How to Stay Protected

To reduce the risk of infection from threats like this one, users should avoid downloading software from untrusted sources, be cautious with email attachments and links from unknown senders, and keep their operating system and applications updated with the latest security patches. Using strong, unique passwords for different accounts and enabling multi-factor authentication where possible can also limit the damage if credentials are stolen. Regularly backing up important files and running periodic system scans with reputable security tools can help detect and remove threats before they cause significant harm.

Analysis Report

General information

Family Name: Backdoor.PSW.Agent.KFC
Signature status: No Signature

Known Samples

MD5: c20e5532159fa3499ff4a266ec8ab0d4
SHA1: e9b1b306476a233b3ca80232fa06630889f066b6
SHA256: 15AFE5642E34DDAA00F364474C9561EF4248A0242BB6A6A0BAECD93730B7195B
File Size: 2.58 MB, 2579968 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • CryptUnprotectData
  • fptable
  • No CryptProtectData
  • No Version Info
  • VirtualQueryEx
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 11,472
Potentially Malicious Blocks: 1,138
Whitelisted Blocks: 10,334
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x x 0 0 x 0 0 x x 0 x x x 0 x 0 0 0 x x x x x x 0 0 0 0 0 0 x 0 x x 0 x 0 0 x x x x x 0 x x x x 0 x 0 x x x x 0 x x 0 x 0 x x x 0 x x 0 0 0 0 0 0 0 0 1 0 x 0 0 x x 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 0 0 x 0 0 0 0 x 0 0 x 0 0 x 0 0 0 0 1 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 0 1 0 0 0 0 0 0 0 0 x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x x x 0 0 0 x 0 x x x x 0 0 x 0 x x 0 0 x 0 x x 0 0 0 0 0 0 0 x x x x 0 x x x x x 0 x x x x x x x 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 x x x 0 x x x x x 0 x x x x 0 x x 0 x 0 0 0 x x x x x x x x x x 0 x x x x x 0 x x 0 0 0 0 0 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 0 x 0 x 0 0 0 0 1 0 x 0 0 x 0 0 1 0 0 0 0 x 0 0 0 0 x 0 x x 0 x 0 x 0 0 x x x x x 0 x x 0 x 0 x x 0 0 x x x x 0 0 x x 0 x x 0 x 0 0 0 x x 0 x x 0 x x 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 x 0 0 0 x 0 0 x 0 0 x 0 0 x x x 0 x x x x x x x x 0 0 x 0 x 0 0 x 0 x x x x x x 0 x 0 0 0 x x x x 0 x 0 x 0 x x x x x x 0 0 x 0 0 x 0 0 x x x 0 x x 0 0 x x 0 0 0 0 0 0 x 0 0 x x x x x x 0 x x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x 0 x x 0 x 0 0 x 0 0 x 0 0 x x 0 x 0 0 0 0 0 0 x 0 x 0 0 0 x 0 0 0 0 x 0 0 x x 0 x 0 0 0 x x 0 x 0 0 0 x 0 0 0 x x x 0 x 0 x x x x x x x x x x x 0 0 0 x x x 0 x x x x x 0 x x 0 x x x x x x 1 x 0 x 0 0 x x 0 x x x x 0 x x x 0 x x 0 x x x x 0 x 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x x x 0 x 0 0 0 0 x 0 0 x 0 0 0 x 1 x x x 1 x 0 0 x 0 x 0 0 x 0 0 0 0 0 0 0 x x 0 x x x x 0 0 0 0 0 x x x x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x x x x x x x x x x x 0 x 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 x 0 x 0 x x x x 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x x x x x 0 x 0 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 x 0 x 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • PSW.Agent.KFC

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtClose
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
Show More
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
Network Winsock2
  • WSAStartup