Benign Download

Trojan-Spy.Win32.PcGhost.340

Image list icon size importExecute shell command (ShellExecuteA)
SHA-25643a91ef03538e594f02fdbf9529cb12beb00ef8e1e3a6a0463da817d76a6113f
MaleculeH₂(PoU)

Evidence

Query/set system parameters (symbol) 0x7f4c4–0x7f5b4
0x7f4c48607080094070800a6070800b2070800................
0x7f4d4c0070800d0070800e0070800f4070800................
0x7f4e408080800140808002a0808003e080800........*...>...
0x7f4f45608080068080800720808008a080800V...h...r.......
0x7f50498080800a8080800ba080800c8080800................
⋯11 more rows
Execute shell command (ShellExecuteA) 0x7f604–0x7f874
⋯23 more rows
0x7f774801208009612080000000000ba120800................
0x7f78400000000d6120800ee12080006130800................
0x7f794181308002a1308004413080060130800....*...D...`...
0x7f7a48013080096130800ac130800c2130800................
0x7f7b4d6130800ec1308000014080014140800................
0x7f7c4281408003a140800521408006a140800(...:...R...j...
0x7f7d48214080092140800ac140800c0140800................
0x7f7e4d414080000000000f614080000000000................
0x7f7f414150800281508000000000048150800....(.......H...
0x7f8045615080064150800761508008e150800V...d...v.......
⋯7 more rows
Query/set system parameters (string) 0x80844–0x808e4
0x80844736c6174654d4449537973416363656cslateMDISysAccel
0x8085400000000547261636b506f7075704d65....TrackPopupMe
0x808646e7500000000546f4173636969000000nu....ToAscii...
0x8087453797374656d506172616d6574657273SystemParameters
0x80884496e666f4100000053686f7757696e64InfoA...ShowWind
0x808946f770000000053686f775363726f6c6cow....ShowScroll
⋯5 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.