Benign Download

Trojan-Downloader.Win32.Banload.vwn

Image list icon size importExecute shell command (ShellExecuteA)
SHA-25657df17ae8175eec64efb5004f10decd075acf512f615cfe36adab7b1d31a1815
MaleculeH₂(PoU)

Evidence

Query/set system parameters (string) 0x54424–0x544c4
0x54424654d65737361676500005472616e736ceMessage..Transl
0x544346174654d4449537973416363656c0000ateMDISysAccel..
0x54444547261636b506f7075704d656e750000TrackPopupMenu..
0x5445453797374656d506172616d6574657273SystemParameters
0x54464496e666f4100000053686f7757696e64InfoA...ShowWind
0x544746f77000053686f775363726f6c6c4261ow..ShowScrollBa
⋯5 more rows
Query/set system parameters (symbol) 0x5642c–0x565ec
0x5642c00000000000000000000000000000000................
0x5643c00000000000000000000000000000000................
0x5644c00000000000000000000000000000000................
0x5645c00000000000000000000000000000000................
0x5646c00000000000000000000000000000000................
⋯24 more rows
Execute shell command (ShellExecuteA) 0x56608–0x567d8
⋯13 more rows
0x566d800000000000000000000000000000000................
0x566e800000000000000000000000000000000................
0x566f800000000000000000000000000000000................
0x5670800000000000000000000000000000000................
0x5671800000000000000000000000000000000................
0x5672800000000000000000000000000000000................
0x5673800000000000000000000000000000000................
0x5674800000000000000000000000000000000................
0x5675800000000000000000000000000000000................
0x5676800000000000000000000000000000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.