Benign Download

Trojan-Downloader.Win32.Banload.hih

CreateRemoteThread API referenceCreateRemoteThread API string
SHA-2568cf5d6450bb030abdcdf644d8662278809715f8c868e4f1a9e389f5365f172b9
MaleculeH₂(PoU)

Evidence

CreateRemoteThread API string 0x589c4–0x58a94
⋯3 more rows
0x589f443726561746554687265616400000000CreateThread....
0x58a0443726561746552656d6f746554687265CreateRemoteThre
0x58a1461640000000043726561746546696c65ad....CreateFile
0x58a244d617070696e67410000000043726561MappingA....Crea
⋯7 more rows
Query/set system parameters (string) 0x58ede–0x58f7e
0x58ede6765000000005472616e736c6174654dge....TranslateM
0x58eee4449537973416363656c000000005472DISysAccel....Tr
0x58efe61636b506f7075704d656e7500000000ackPopupMenu....
0x58f0e53797374656d506172616d6574657273SystemParameters
0x58f1e496e666f4100000053686f7757696e64InfoA...ShowWind
0x58f2e6f770000000053686f775363726f6c6cow....ShowScroll
⋯5 more rows
CreateRemoteThread API reference 0x5a348–0x5a418
⋯3 more rows
0x5a37862366a3672367a3682368a3692369a36b6j6r6z6.6.6.6.6
0x5a388a236aa36b236ba36c236ca36d236da36.6.6.6.6.6.6.6.6
0x5a398e236ea36f236fa3602370a3712371a37.6.6.6.6.7.7.7.7
0x5a3a822372a3732373a3742374a3752375a37"7*727:7B7J7R7Z7
⋯7 more rows
Query/set system parameters (symbol) 0x5a484–0x5a574
0x5a484e03ce83cf03cf83c003d083d103d183d.<.<.<.<.=.=.=.=
0x5a494203d283d303d383d403d483d503d583d =(=0=8=@=H=P=X=
0x5a4a4603d683d703d783d803d883d903d983d`=h=p=x=.=.=.=.=
0x5a4b4a03da83db03db83dc03dc83dd03dd83d.=.=.=.=.=.=.=.=
0x5a4c4e03de83df03df83d003e083e103e183e.=.=.=.=.>.>.>.>
⋯11 more rows
Image list icon size import 0x5a658–0x5a7e8
⋯12 more rows
0x5a7185c377037903798379c37a037a437a837\7p7.7.7.7.7.7.7
0x5a728ac37b037b437b837d037f037f837fc37.7.7.7.7.7.7.7.7
0x5a7380038043808380c381038143818382c38.8.8.8.8.8.8.8,8
0x5a7484c38543858385c386038643868386c38L8T8X8\8`8d8h8l8
⋯10 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.