Trojan-Downloader.Win32.Obfuscated.ijm
IsDebuggerPresent API name in PE stringsReferences the IsDebuggerPresent API
SHA-256bf5a57706354a653f4420c945065ad66ec66f547258083dfbdb4a912037c57f5
MaleculeH₂(PoU)
Evidence
⋯3 more rows
0x3108832030700440307005c030700700307002...D...\...p...
0x310988a030700a203070000000000cb030700................
0x310a800000000f1030700090407001d040700................
0x310b8310407003f0407004d040700650407001...?...M...e...
⋯7 more rows
⋯3 more rows
0x3116cb5070700c3070700d5070700e7070700................
0x3117cf3070700070807001d08070035080700............5...
0x3118c4f080700670807007d08070095080700O...g...}.......
0x3119ca5080700b3080700cd080700e5080700................
⋯7 more rows
⋯3 more rows
0x707e500009403577269746546696c65002f02....WriteFile./.
0x707f54973446562756767657250726573656eIsDebuggerPresen
0x708057400560147657446696c654174747269t.V.GetFileAttri
0x7081562757465734100008e01476574507269butesA....GetPri
⋯7 more rows