Benign Download

Trojan-Downloader.Win32.Agent.bhqb

CreateRemoteThread API referenceCreateRemoteThread API string
SHA-256cfe5c8a74454ce8400ef736b858932e1e8c0e72822f8d535286f36b3a2f7b7b2
MaleculeH₃(DbPoU)

Evidence

ConnectionString property 0x7ce66–0x7cf26
⋯3 more rows
0x7ce965441444f436f6e6e656374696f6e0110TADOConnection..
0x7cea6436f6e6e656374696f6e537472696e67ConnectionString
0x7ceb60a57696465537472696e670106557365.WideString..Use
⋯7 more rows
CreateRemoteThread API string 0x9955a–0x9962a
⋯3 more rows
0x9958a43726561746554687265616400000000CreateThread....
0x9959a43726561746552656d6f746554687265CreateRemoteThre
0x995aa61640000000043726561746546696c65ad....CreateFile
0x995ba410000004372656174654576656e7441A...CreateEventA
⋯7 more rows
Query/set system parameters (string) 0x99b88–0x99c28
0x99b886765000000005472616e736c6174654dge....TranslateM
0x99b984449537973416363656c000000005472DISysAccel....Tr
0x99ba861636b506f7075704d656e7500000000ackPopupMenu....
0x99bb853797374656d506172616d6574657273SystemParameters
0x99bc8496e666f4100000053686f7757696e64InfoA...ShowWind
0x99bd86f770000000053686f775363726f6c6cow....ShowScroll
⋯5 more rows
CreateRemoteThread API reference 0x9a3d4–0x9a4a4
⋯3 more rows
0x9a4040000000044656657696e646f7750726f....DefWindowPro
0x9a4146341000000004465664d44494368696ccA....DefMDIChil
0x9a4246450726f634100000000446566467261dProcA....DefFra
0x9a4346d6550726f6341000000437265617465meProcA...Create
⋯7 more rows
Image list icon size import 0x9a828–0x9a928
⋯3 more rows
0x9a85867437572736f72496d61676500000000gCursorImage....
0x9a868496d6167654c6973745f447261674d6fImageList_DragMo
0x9a878766500000000496d6167654c6973745fve....ImageList_
0x9a888447261674c65617665000000496d6167DragLeave...Imag
⋯10 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.