Benign Download

Worm.Win32.Runfer.ku

Image list icon size importExecute shell command (ShellExecuteA)
SHA-256ae78f1813c96535532be71ac89259f51b7b84edbaf9fcd2f97db58af04e06e1a
MaleculeH₂(PoU)

Evidence

Query/set system parameters (string) 0xa2798–0xa2838
0xa27986765000000005472616e736c6174654dge....TranslateM
0xa27a84449537973416363656c000000005472DISysAccel....Tr
0xa27b861636b506f7075704d656e7500000000ackPopupMenu....
0xa27c853797374656d506172616d6574657273SystemParameters
0xa27d8496e666f4100000053686f7757696e64InfoA...ShowWind
0xa27e86f770000000053686f775363726f6c6cow....ShowScroll
⋯5 more rows
Query/set system parameters (symbol) 0xa5624–0xa5714
0xa562448324c325032543258325c3260326432H2L2P2T2X2\2`2d2
0xa56347432843288329832b732d832f8320033t2.2.2.2.2.2.2.3
0xa5644043308330c331033143318331c332033.3.3.3.3.3.3.3 3
0xa5654243328332c333033343338333c334033$3(3,3034383<3@3
0xa566458336833743378338033843388338c33X3h3t3x3.3.3.3.3
⋯11 more rows
Execute shell command (ShellExecuteA) 0xa5818–0xa59e8
⋯13 more rows
0xa58e85035b335da3509361f367e369b36d036P5.5.5.6.6~6.6.6
0xa58f82137b1371e389b38d138f03840395839!7.7.8.8.8.8@9X9
0xa5908383a713a1c3b343be53bfd3b443c6d3d8:q:.;4;.;.;D<m=
0xa5918953e9c3eed3ef43e483fc03fc73f0000.>.>.>.>H?.?.?..
0xa592800800100b80000001a30213052305930.........0!0R0Y0
0xa5938da30383173318331a331f9325c336333.081s1.1.1.2\3c3
0xa5948c133c833df33c635da35f235f935c736.3.3.3.5.5.5.5.6
0xa5958e836f7360e37ce37d537583864387838.6.6.7.7.7X8d8x8
0xa59688038843888388c389038943898389c38.8.8.8.8.8.8.8.8
0xa5978a038a438b238ba38d038f038f838fc38.8.8.8.8.8.8.8.8
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.