Benign Download

Trojan-GameThief.Win32.OnLineGames.aftn

Image list icon size importExecute shell command (ShellExecuteA)
SHA-2563db5fec23b2f43f5b9c97dcdaab5d29f4087695974c8d7db995ca933592d00ab
MaleculeH₂(PoU)

Evidence

Query/set system parameters (symbol) 0x604cc–0x605bc
0x604cc17ee09002aee09000000000033ee0900....*.......3...
0x604dc45ee090057ee090062ee090070ee0900E...W...b...p...
0x604ec7fee090092ee0900a8ee0900bbee0900................
0x604fcd2ee0900e3ee0900fbee090008ef0900................
0x6050c18ef09002aef090037ef09004bef0900....*...7...K...
⋯11 more rows
Execute shell command (ShellExecuteA) 0x606bc–0x6088c
⋯13 more rows
0x6078cd6f80900e8f80900fcf809000af90900................
0x6079c19f909000000000027f909003ff90900........'...?...
0x607ac57f9090069f909007af9090093f90900W...i...z.......
0x607bcaef90900cdf90900e2f90900f8f90900................
0x607cc0efa090022fa090038fa09004bfa0900...."...8...K...
0x607dc5efa09006ffa090086fa09009dfa0900^...o...........
0x607ecb5fa0900c5fa0900dffa0900f3fa0900................
0x607fc0000000006fb09000000000016fb0900................
0x6080c34fb090047fb090065fb09007bfb09004...G...e...{...
0x6081c8afb09009bfb0900abfb0900bcfb0900................
⋯7 more rows
Query/set system parameters (string) 0x72ed6–0x72f76
0x72ed6616e736c6174654d6573736167655472anslateMessageTr
0x72ee6616e736c6174654d4449537973416363anslateMDISysAcc
0x72ef6656c547261636b506f7075704d656e75elTrackPopupMenu
0x72f0653797374656d506172616d6574657273SystemParameters
0x72f16496e666f4153686f7757696e646f7753InfoAShowWindowS
0x72f26686f775363726f6c6c42617253686f77howScrollBarShow
⋯5 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.