Benign Download

Backdoor.Win32.Wootbot.fm

Encoded content decoded: base64IsDebuggerPresent API name in PE strings
SHA-2564f822154830f35890fc51357f6140f24f3e5e66b08879f5dbeb2ba77075f7dbf
MaleculeH(Po)Md

Evidence

IsDebuggerPresent API name in PE strings 0xa1358–0xa1428
⋯3 more rows
0xa138820546f6f6c7300000000000000000000 Tools..........
0xa13984973446562756767657250726573656eIsDebuggerPresen
0xa13a874000000000000004b45524e454c3332t.......KERNEL32
0xa13b82e444c4c000000005c5c2e5c4e544943.DLL....\\.\NTIC
⋯7 more rows
Encoded content decoded: base64 0xa1c58–0xa1d28
⋯3 more rows
0xa1c884011410010a0410040a2410001000000@[email protected].....
0xa1c98363636363636363636363636363636366666666666666666
0xa1ca8363636363636363636363636363636366666666666666666
0xa1cb8363636363636363636363636363636366666666666666666
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.