Benign Download

Trojan-Downloader.Win32.Dadobra.xq

Image list icon size importExecute shell command (ShellExecuteA)
SHA-256401f6b96985376c82a4c747567a9fa2c316590bd012f3451e61a9a4d80505d4c
MaleculeH₂(PoU)

Evidence

Query/set system parameters (string) 0x4edcc–0x4ee6c
0x4edcc6765000000005472616e736c6174654dge....TranslateM
0x4eddc4449537973416363656c000000005472DISysAccel....Tr
0x4edec61636b506f7075704d656e7500000000ackPopupMenu....
0x4edfc53797374656d506172616d6574657273SystemParameters
0x4ee0c496e666f4100000053686f7757696e64InfoA...ShowWind
0x4ee1c6f770000000053686f775363726f6c6cow....ShowScroll
⋯5 more rows
Query/set system parameters (symbol) 0x5141c–0x5150c
0x5141c8c399039943998399c39a039a439a839.9.9.9.9.9.9.9.9
0x5142cac39b039b439b839bc39c839e839f039.9.9.9.9.9.9.9.9
0x5143cf439f839fc39003a043a083a0c3a103a.9.9.9.:.:.:.:.:
0x5144c143a183a1c3a203a243a283a2c3a403a.:.:.: :$:(:,:@:
0x5145c603a683a6c3a703a743a783a7c3a803a`:h:l:p:t:x:|:.:
⋯11 more rows
Execute shell command (ShellExecuteA) 0x515ec–0x517ac
⋯12 more rows
0x516acf033f433f833fc330034043414343434.3.3.3.3.4.4.444
0x516bc3c344034443448344c34503454345834<4@4D4H4L4P4T4X4
0x516cc5c346e357d358c35c0360e3715373637\4n5}5.5.6.7.767
0x516dc9738ae38b5387539e5391a3a2c3a433a.8.8.8u9.9.:,:C:
0x516ecc73b673c773c843c953ca03cb33ce93c.;g<w<.<.<.<.<.<
0x516fcfc3c2c3d313dac3db93d003e053e3e3e.<,=1=.=.=.>.>>>
0x5170c593e683e7f3ea03ead3eba3ecf3ed43eY>h>.>.>.>.>.>.>
0x5171c133f203f2f3f3a3f4c3f623f673f833f.? ?/?:?L?b?g?.?
0x5172c903f9d3faf3fb43fcf3fdc3fe93ffb3f.?.?.?.?.?.?.?.?
0x5173c00300100bc00000000301e302b303a30.0.......0.0+0:0
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.