Benign Download

Trojan-Downloader.Win32.Dadobra.aqa

Image list icon size importExecute shell command (ShellExecuteA)
SHA-256696f2c1c4c3b0fe4446b5d1bfaba79a319d2077c8e171aca33562c6bb36a7003
MaleculeH₂(PoU)

Evidence

Query/set system parameters (string) 0x4eb0c–0x4ebac
0x4eb0c654d65737361676500005472616e736ceMessage..Transl
0x4eb1c6174654d4449537973416363656c0000ateMDISysAccel..
0x4eb2c547261636b506f7075704d656e750000TrackPopupMenu..
0x4eb3c53797374656d506172616d6574657273SystemParameters
0x4eb4c496e666f4100000053686f7757696e64InfoA...ShowWind
0x4eb5c6f77000053686f775363726f6c6c4261ow..ShowScrollBa
⋯5 more rows
Query/set system parameters (symbol) 0x50404–0x505b4
0x5040400000000000000000000000000000000................
0x5041400000000000000000000000000000000................
0x5042400000000000000000000000000000000................
0x5043400000000000000000000000000000000................
0x5044400000000000000000000000000000000................
⋯23 more rows
Execute shell command (ShellExecuteA) 0x505d0–0x50790
⋯12 more rows
0x5069000000000000000000000000000000000................
0x506a000000000000000000000000000000000................
0x506b000000000000000000000000000000000................
0x506c000000000000000000000000000000000................
0x506d000000000000000000000000000000000................
0x506e000000000000000000000000000000000................
0x506f000000000000000000000000000000000................
0x5070000000000000000000000000000000000................
0x5071000000000000000000000000000000000................
0x5072000000000000000000000000000000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.