Benign Download

Trojan-Downloader.Win32.Agent.ecm

Image list icon size importExecute shell command (ShellExecuteA)
SHA-2562b5aee5ac95ae5f246156ab319d54267f1d2bb596002446ba918f3d68f23f0f1
MaleculeH₂(PoU)

Evidence

Query/set system parameters (string) 0x5a8d8–0x5a978
0x5a8d86765000000005472616e736c6174654dge....TranslateM
0x5a8e84449537973416363656c000000005472DISysAccel....Tr
0x5a8f861636b506f7075704d656e7500000000ackPopupMenu....
0x5a90853797374656d506172616d6574657273SystemParameters
0x5a918496e666f4100000053686f7757696e64InfoA...ShowWind
0x5a9286f770000000053686f775363726f6c6cow....ShowScroll
⋯5 more rows
Query/set system parameters (symbol) 0x5c430–0x5c520
0x5c430f53d123e1a3e223e423e8b3eb93edc3e.=.>.>">B>.>.>.>
0x5c440f93e423f623f8c3fa63fc43f00c00000.>B?b?.?.?.?....
0x5c450bc0000001c303b308c30c0300c317431.....0;0.0.0.1t1
0x5c460b131e131f5311b322f328e32cb322834.1.1.1.2/2.2.2(4
0x5c4706f349b34c934ed34f93412351c352635o4.4.4.4.4.5.5&5
⋯11 more rows
Execute shell command (ShellExecuteA) 0x5c610–0x5c7e0
⋯13 more rows
0x5c6e0bd3bc33bc83bd33bd93bde3be93bef3b.;.;.;.;.;.;.;.;
0x5c6f0f43bff3b053c0a3c153c1b3c203c2b3c.;.;.<.<.<.< <+<
0x5c700313c363c413c473c4c3c573c5d3c623c1<6<A<G<L<W<]<b<
0x5c7106d3c733c783c833c893c8e3c993c9f3cm<s<x<.<.<.<.<.<
0x5c720a43caf3cb53cba3cc53ccb3cd03cdb3c.<.<.<.<.<.<.<.<
0x5c730e13ce63cf13cf73cfc3c073d0d3d123d.<.<.<.<.<.=.=.=
0x5c7401d3d233d283d333d393d3e3d493d6b3e.=#=(=3=9=>=I=k>
0x5c750773e843e963ec63eca3ece3ee63ef43ew>.>.>.>.>.>.>.>
0x5c760f83e143f1c3f203f243f283f2c3f303f.>.?.? ?$?(?,?0?
0x5c770343f383f3c3f403f443f483f4c3f503f4?8?<?@?D?H?L?P?
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.