Suspicious 80% Download

Backdoor.Win32.Rbot.ivs

Named Rbot backdoor

IsDebuggerPresent API name in PE stringsPercent-encoded content decoded
SHA-256510856d77557c9968e92fe08db2c491aec51c86186d47113a8a9e96f725b0389
MaleculeH(Po)Md

Evidence

Percent-encoded content decoded 0x1bd6c–0x1be3c
3 more rows
0x1bd9c66726565206661696c7572652e0a0000free failure....
0x1bdac6d656d6f727920636865636b20657272memory check err
0x1bdbc6f7220617420307825303858203d2030or at 0x%08X = 0
0x1bdcc78253032582c2073686f756c64206265x%02X, should be
7 more rows
IsDebuggerPresent API name in PE strings 0x2edf7–0x2eea7
3 more rows
0x2ee274d657373616765426f78410000000000MessageBoxA.....
0x2ee374973446562756767657250726573656eIsDebuggerPresen
0x2ee4774000000000000000000000000000000t...............
0x2ee5700000000000000000000000000000000................
5 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.