Suspicious 80% Download

Backdoor.Win32.Havar.bz

Named backdoor, packed, shell exec

Binary contains a UPX packing markerUPX decompression I/O error
SHA-25677673cf340532c9f36588baf0115564d79f0ee8dcaafeac4616de215d8b629cd
MaleculeH₂(PoU)

Evidence

Query/set system parameters (symbol) 0x8552c–0x8561c
0x8552c86d10900000000009cd10900aed10900................
0x8553cbcd10900ced10900dad10900e8d10900................
0x8554cf8d109000cd2090022d2090036d20900........"...6...
0x8555c4ed2090060d2090078d2090086d20900N...`...x.......
0x8556c96d20900a8d20900b6d20900c6d20900................
⋯11 more rows
Execute shell command (ShellExecuteA) 0x85724–0x85914
⋯15 more rows
0x8581462dd090076dd090088dd090000000000b...v...........
0x85824a6dd0900b6dd090000000000d4dd0900................
0x85834ecdd090004de090016de090028de0900............(...
0x8584442de09005ede09007ede090094de0900B...^...~.......
0x85854aade0900c0de0900d4de0900eade0900................
0x85864fede090012df090024df09003cdf0900........$...<...
0x8587454df09006cdf09007cdf090096df0900T...l...|.......
0x85884aadf090000000000cadf090000000000................
0x85894e6df0900f4df090002e0090014e00900................
0x858a42ce0090044e009005ce009006ee00900,...D...\...n...
⋯7 more rows
Query/set system parameters (string) 0x99190–0x99230
0x99190654d65737361676500015472616e736ceMessage..Transl
0x991a06174654d4449537973416363656c0001ateMDISysAccel..
0x991b0547261636b506f7075704d656e750001TrackPopupMenu..
0x991c053797374656d506172616d6574657273SystemParameters
0x991d0496e666f41000153686f7757696e646fInfoA..ShowWindo
0x991e077000153686f775363726f6c6c426172w..ShowScrollBar
⋯5 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.