Benign Download

Trojan-Spy.Win32.Delf.dvm

Image list icon size importExecute shell command (ShellExecuteA)
SHA-256afd8bc859112c535f9c9924ec5bb31a922a3c7643b4aa4ca09e7148aaced3d64
MaleculeH₂(PoU)

Evidence

Query/set system parameters (string) 0x8f204–0x8f2a4
0x8f2046765000000005472616e736c6174654dge....TranslateM
0x8f2144449537973416363656c000000005472DISysAccel....Tr
0x8f22461636b506f7075704d656e7500000000ackPopupMenu....
0x8f23453797374656d506172616d6574657273SystemParameters
0x8f244496e666f4100000053686f7757696e64InfoA...ShowWind
0x8f2546f770000000053686f775363726f6c6cow....ShowScroll
⋯5 more rows
Query/set system parameters (symbol) 0x91558–0x91648
0x91558483d683d703d743d783d7c3d803d843dH=h=p=t=x=|=.=.=
0x91568883d8c3d903db03dd03dd83ddc3de03d.=.=.=.=.=.=.=.=
0x91578e43de83dec3df03df43df83d143e343e.=.=.=.=.=.=.>4>
0x915883c3e403e443e483e4c3e503e543e583e<>@>D>H>L>P>T>X>
0x915985c3e813e8f3e9e3eb53ee73e233f323f\>.>.>.>.>.>#?2?
⋯11 more rows
Execute shell command (ShellExecuteA) 0x91848–0x91968
⋯3 more rows
0x91878ee39f239f639fa39fe39023a063a0a3a.9.9.9.9.9.:.:.:
0x918880e3a123a163a1a3a1e3a223a263a2a3a.:.:.:.:.:":&:*:
0x918982e3a323a423a053b683b8c3b123c723c.:2:B:.;h;.;.<r<
0x918a8bc3cfe3c173d303db03db43db83dbc3d.<.<.=0=.=.=.=.=
0x918b8c03dc43dc83dcc3dd03dd43dd83ddc3d.=.=.=.=.=.=.=.=
0x918c8e03de43de83dec3df03df43df83dfc3d.=.=.=.=.=.=.=.=
0x918d8003e043e183e7b3f7f3f833f873f8b3f.>.>.>{?.?.?.?.?
0x918e88f3f933f973f9b3f9f3fa33fa73fab3f.?.?.?.?.?.?.?.?
0x918f8af3fb33fb73fbb3fbf3fc33fc73fcb3f.?.?.?.?.?.?.?.?
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.