Benign Download

Backdoor.Win32.Psyf.18

Image list icon size importExecute shell command (ShellExecuteA)
SHA-25604e78056b9522372e128c77618b437b703eb465aa4a88fcaa97b4aeb1b6e08bf
MaleculeH₂(PoU)

Evidence

Query/set system parameters (string) 0x6faec–0x6fb8c
0x6faec6765000000005472616e736c6174654dge....TranslateM
0x6fafc4449537973416363656c000000005472DISysAccel....Tr
0x6fb0c61636b506f7075704d656e7500000000ackPopupMenu....
0x6fb1c53797374656d506172616d6574657273SystemParameters
0x6fb2c496e666f4100000053686f7757696e64InfoA...ShowWind
0x6fb3c6f770000000053686f775363726f6c6cow....ShowScroll
⋯5 more rows
Query/set system parameters (symbol) 0x71490–0x71570
0x7149000000000000000000000000000000000................
0x714a000000000000000000000000000000000................
0x714b000000000000000000000000000000000................
0x714c000000000000000000000000000000000................
0x714d000000000000000000000000000000000................
⋯10 more rows
Execute shell command (ShellExecuteA) 0x715b0–0x71820
⋯23 more rows
0x7172000000000000000000000000000000000................
0x7173000000000000000000000000000000000................
0x7174000000000000000000000000000000000................
0x7175000000000000000000000000000000000................
0x7176000000000000000000000000000000000................
0x7177000000000000000000000000000000000................
0x7178000000000000000000000000000000000................
0x7179000000000000000000000000000000000................
0x717a000000000000000000000000000000000................
0x717b000000000000000000000000000000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.