Benign Download

Trojan-Spy.Win32.Delf.cqx

Image list icon size importExecute shell command (ShellExecuteA)
SHA-256cf4cb39c0743636b523140c1cb3a46e51ee8b36f3a6fd946643f582c368d224b
MaleculeH₂(PoU)

Evidence

Query/set system parameters (string) 0x6b1d2–0x6b272
0x6b1d26765000000005472616e736c6174654dge....TranslateM
0x6b1e24449537973416363656c000000005472DISysAccel....Tr
0x6b1f261636b506f7075704d656e7500000000ackPopupMenu....
0x6b20253797374656d506172616d6574657273SystemParameters
0x6b212496e666f4100000053686f7757696e64InfoA...ShowWind
0x6b2226f770000000053686f775363726f6c6cow....ShowScroll
⋯5 more rows
Query/set system parameters (symbol) 0x6d460–0x6d540
0x6d460a63a243b393b4e3b533b603b803b9a3b.:$;9;N;S;`;.;.;
0x6d4709f3b713cd23cdf3cfa3c003d143d193d.;q<.<.<.<.=.=.=
0x6d480f93d1e3e2b3e363e573e6d3e853e8a3e.=.>+>6>W>m>.>.>
0x6d490bf3ece3edb3ee63ef93e063f4e3f533f.>.>.>.>.>.?N?S?
0x6d4a06d3f9b3fa73fb33fbd3fc33fcd3fd83fm?.?.?.?.?.?.?.?
⋯10 more rows
Execute shell command (ShellExecuteA) 0x6d630–0x6d7f0
⋯12 more rows
0x6d6f04031603168316c317031743178317c31@1`1h1l1p1t1x1|1
0x6d7008031843188318c31903194319831a431.1.1.1.1.1.1.1.1
0x6d710c431cc31d031d431d831dc31e031e431.1.1.1.1.1.1.1.1
0x6d720e831ec31fc311c32243228322c323032.1.1.1.2$2(2,202
0x6d730343238323c3240324432503260326c324282<2@2D2P2`2l2
0x6d740703278327c328032843288328c329032p2x2|2.2.2.2.2.2
0x6d750943298329c32a032a432ae32b232c432.2.2.2.2.2.2.2.2
0x6d760d532d932113315331933313340334433.2.2.3.3.313@3D3
0x6d7704c335033603368336c33703374337833L3P3`3h3l3p3t3x3
0x6d7807c338033843388338c33903394339833|3.3.3.3.3.3.3.3
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.