Benign Download

Trojan-Spy.Win32.KeyLogger.ek

Image list icon size importExecute shell command (ShellExecuteA)
SHA-256a8aecf537100639710614f9877eb878b561551562584ebf2b382b2652b39b86a
MaleculeH₂(PoU)

Evidence

Query/set system parameters (string) 0x507d2–0x50872
0x507d2654d65737361676500005472616e736ceMessage..Transl
0x507e26174654d4449537973416363656c0000ateMDISysAccel..
0x507f2547261636b506f7075704d656e750000TrackPopupMenu..
0x5080253797374656d506172616d6574657273SystemParameters
0x50812496e666f4100000053686f7757696e64InfoA...ShowWind
0x508226f77000053686f775363726f6c6c4261ow..ShowScrollBa
⋯5 more rows
Query/set system parameters (symbol) 0x52424–0x525e4
0x5242400000000000000000000000000000000................
0x5243400000000000000000000000000000000................
0x5244400000000000000000000000000000000................
0x5245400000000000000000000000000000000................
0x5246400000000000000000000000000000000................
⋯24 more rows
Execute shell command (ShellExecuteA) 0x525f4–0x527b4
⋯12 more rows
0x526b400000000000000000000000000000000................
0x526c400000000000000000000000000000000................
0x526d400000000000000000000000000000000................
0x526e400000000000000000000000000000000................
0x526f400000000000000000000000000000000................
0x5270400000000000000000000000000000000................
0x5271400000000000000000000000000000000................
0x5272400000000000000000000000000000000................
0x5273400000000000000000000000000000000................
0x5274400000000000000000000000000000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.