Benign Download

Backdoor.Win32.Delf.dll

Image list icon size importExecute shell command (ShellExecuteA)
SHA-256721aa58140d18aec1f679bb88d4be913d83f9db5fb95143d452bcff015ad701e
MaleculeH₂(PoU)

Evidence

Query/set system parameters (string) 0x7b796–0x7b836
0x7b7966765000000005472616e736c6174654dge....TranslateM
0x7b7a64449537973416363656c000000005472DISysAccel....Tr
0x7b7b661636b506f7075704d656e7500000000ackPopupMenu....
0x7b7c653797374656d506172616d6574657273SystemParameters
0x7b7d6496e666f4100000053686f7757696e64InfoA...ShowWind
0x7b7e66f770000000053686f775363726f6c6cow....ShowScroll
⋯5 more rows
Query/set system parameters (symbol) 0x7d618–0x7d708
0x7d618e83df03df43df83dfc3d003e043e083e.=.=.=.=.=.>.>.>
0x7d6280c3e103e243e443e4c3e503e543e583e.>.>$>D>L>P>T>X>
0x7d6385c3e603e643e683e6c3e7c3e9c3ea43e\>`>d>h>l>|>.>.>
0x7d648a83eac3eb03eb43eb83ebc3ec03ec43e.>.>.>.>.>.>.>.>
0x7d658d43ef43efc3e003f043f083f0c3f103f.>.>.>.?.?.?.?.?
⋯11 more rows
Execute shell command (ShellExecuteA) 0x7d900–0x7da30
⋯3 more rows
0x7d930cd3fd53fdd3fe53fed3f000000a00000.?.?.?.?.?......
0x7d94050000000523081309c30a030a430a830P...R0.0.0.0.0.0
0x7d950ac30e93126333b334634d534e7348f35.0.1&3;3F4.4.4.5
0x7d960d136eb36f5365b37a03777383539473a.6.6.6[7.7w859G:
0x7d970d33a3b3c223d583da93dd63d3a3e843e.:;<"=X=.=.=:>.>
0x7d980bf3ece3e3d3f8b3fd93f000000b00000.>.>=?.?.?......
0x7d990b80000004c3053309030943098309c30....L0S0.0.0.0.0
0x7d9a0a030a430a830ac30b030b430b830bc30.0.0.0.0.0.0.0.0
0x7d9b0c030c430c830cc30b531cf312d325432.0.0.0.0.1.1-2T2
0x7d9c068327c32ad32ed3202331733f9330d34h2|2.2.2.3.3.3.4
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.