Benign Download

Trojan-Downloader.Win32.Banload.mpn

Image list icon size importExecute shell command (ShellExecuteA)
SHA-256918b61d85f70c15aad27f67998b59867bb893a21b7c26e0985cc3e06a1ceb71c
MaleculeH₂(PoU)

Evidence

Query/set system parameters (string) 0x4e362–0x4e402
0x4e3626765000000005472616e736c6174654dge....TranslateM
0x4e3724449537973416363656c000000005472DISysAccel....Tr
0x4e38261636b506f7075704d656e7500000000ackPopupMenu....
0x4e39253797374656d506172616d6574657273SystemParameters
0x4e3a2496e666f4100000053686f7757696e64InfoA...ShowWind
0x4e3b26f770000000053686f775363726f6c6cow....ShowScroll
⋯5 more rows
Query/set system parameters (symbol) 0x503ec–0x504dc
0x503ec533c603c803c9a3c9f3c713dd23ddf3dS<`<.<.<.<q=.=.=
0x503fcfa3d003e143e193ef93e1e3f2b3f363f.=.>.>.>.>.?+?6?
0x5040c573f6d3f853f8a3fbf3fce3fdb3fe63fW?m?.?.?.?.?.?.?
0x5041cf93f000000000100d401000006304e30.?...........0N0
0x5042c53306d309b30a730b330bd30c330cd30S0m0.0.0.0.0.0.0
⋯11 more rows
Execute shell command (ShellExecuteA) 0x505bc–0x5077c
⋯12 more rows
0x5067c0c321032143218321c32283248325032.2.2.2.2.2(2H2P2
0x5068c543258325c326032643268326c327032T2X2\2`2d2h2l2p2
0x5069c8032a032a832ac32b032b432b832bc32.2.2.2.2.2.2.2.2
0x506acc032c432c832d432e432f032f432fc32.2.2.2.2.2.2.2.2
0x506bc0033043308330c331033143318331c33.3.3.3.3.3.3.3.3
0x506cc20332433283332333633483359335d33 3$3(32363H3Y3]3
0x506dc953399339d33b533c433c833d033d433.3.3.3.3.3.3.3.3
0x506ece433ec33f033f433f833fc3300340434.3.3.3.3.3.3.4.4
0x506fc08340c341034143418341c342a344834.4.4.4.4.4.4*4H4
0x5070c6334673478348d34b034bc34c034d034c4g4x4.4.4.4.4.4
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.