Benign Download

Backdoor.Win32.VB.esp

Detects Base64 encoded Executable in ExecutableEncoded content decoded: base64
SHA-25673236264f883432ba89f43d7056ff3dfad190ba41bddf03796ea464c045c2290
MaleculeMdTh

Evidence

Query/set system parameters (string) 0x7154–0x71f4
0x715400000400548c42000000000000000000....T.B.........
0x7164a15c8c42000bc07402ffe0684c714000.\.B...t...hLq@.
0x7174b860114000ffd0ffe000000016000000.`.@............
0x718453797374656d506172616d6574657273SystemParameters
0x7194496e666f41000000d86c400084714000[email protected]@.
0x71a400000400608c42000000000000000000....`.B.........
⋯5 more rows
Encoded content decoded: base64 0xcc78–0xcd68
⋯3 more rows
0xcca8740075007000700000000000a8000000t.u.p.p.........
0xccb853004500740046005700560039004d00S.E.t.F.W.V.9.M.
0xccc8540030004e0042005400460039004e00T.0.N.B.T.F.9.N.
0xccd8510055004e0049005300550035004600Q.U.N.I.S.U.5.F.
0xcce8580046004e00500052006c0052005800X.F.N.P.R.l.R.X.
0xccf8510056004a0046005800450031004a00Q.V.J.F.X.E.1.J.
⋯7 more rows
Detects Base64 encoded Executable in Executable 0x2c45b–0x2c5db
⋯7 more rows
0x2c4cb9868040070006c006700310040340200.h..p.l.g.1.@4..
0x2c4db5400560071005100410041004d004100T.V.q.Q.A.A.M.A.
0x2c4eb41004100410045004100410041004100A.A.A.E.A.A.A.A.
⋯15 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.