Suspicious 86% windows Download

laurentiu021.SysManager v1.103.0

Unsigned, embedded PE, VM checks

Authenticode chain CN: .NET DACCert chain has only 2 entries

Evidence

English function-word token "this" 0x0–0xb0
0x04d5a90000300000004000000ffff0000MZ..............
0x10b8000000000000004000000000000000........@.......
0x2000000000000000000000000000000000................
0x3000000000000000000000000018010000................
0x400e1fba0e00b409cd21b8014ccd215468........!..L.!Th
0x5069732070726f6772616d2063616e6e6fis program canno
⋯6 more rows
Dense x64 TLS-array pointer access 0x3c0–0x480
⋯3 more rows
0x3f000000000000000000000000000000000................
0x40065488b042558000000ba28020000488beH..%X....(...H.
0x4100848c7040a00000000488d0dd0676600.H.......H...gf.
⋯7 more rows
Immediate process-information class value 31 0x12bbf–0x12c7f
⋯3 more rows
0x12befcc48895c24084889742410574883ec40.H.\$.H.t$.WH..@
0x12bffba1f000000488d0d951a6e00e8b0f601.....H....n.....
0x12c0f004533c0488d1566050700488bc8488b.E3.H..f...H..H.
⋯7 more rows
Immediate process-information class value 30 0x13586–0x13646
⋯3 more rows
0x135b60100488b0d89937e004533c989742438..H....~.E3..t$8
0x135c6ba1e000000488974243041b802000000.....H.t$0A.....
0x135d6c644242801c744242004000000488905.D$(..D$ ....H..
⋯7 more rows
LoadLibraryExW w/ SYSTEM32 search 0x141eb–0x142bb
⋯3 more rows
0x1421b33c989742438ba5300000048897424303..t$8.S...H.t$0
0x1422b41b800080000c644242801c744242004A......D$(..D$ .
0x1423b000000e87db70100488b0dfe867e0045....}...H....~.E
0x1424b33c989742438ba5400000048897424303..t$8.T...H.t$0
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.