Benign Download

Backdoor.Win32.GF.13

Image list icon size importExecute shell command (ShellExecuteA)
SHA-25647c97522851ab0bf7db157ea834166341ff394ca58604ab8e16f668a99fa079b
MaleculeH₂(PoU)

Evidence

Query/set system parameters (string) 0x478e0–0x47980
0x478e0654d65737361676500005472616e736ceMessage..Transl
0x478f06174654d4449537973416363656c0000ateMDISysAccel..
0x47900547261636b506f7075704d656e750000TrackPopupMenu..
0x4791053797374656d506172616d6574657273SystemParameters
0x47920496e666f4100000053686f7757696e64InfoA...ShowWind
0x479306f77000053686f775363726f6c6c4261ow..ShowScrollBa
⋯5 more rows
Query/set system parameters (symbol) 0x483f4–0x48604
⋯8 more rows
0x4847400000000000000000000000000000000................
0x4848400000000000000000000000000000000................
0x4849400000000000000000000000000000000................
⋯23 more rows
Execute shell command (ShellExecuteA) 0x4861c–0x487fc
⋯10 more rows
0x486bc00000000000000000000000000000000................
0x486cc00000000000000000000000000000000................
0x486dc00000000000000000000000000000000................
0x486ec00000000000000000000000000000000................
⋯7 more rows
0x4876c00000000000000000000000000000000................
0x4877c00000000000000000000000000000000................
0x4878c00000000000000000000000000000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.