Benign Download

Backdoor.Win32.ReverseTrojan.20

Image list icon size importExecute shell command (ShellExecuteA)
SHA-256d0c2141e9fb9db31c2269efad4d24a5541fba50a878cc27a4fcd986ca1a73b7c
MaleculeH₂(PoU)

Evidence

Query/set system parameters (symbol) 0xa34ec–0xa36bc
0xa34ec00000000000000000000000000000000................
0xa34fc00000000000000000000000000000000................
0xa350c00000000000000000000000000000000................
0xa351c00000000000000000000000000000000................
0xa352c00000000000000000000000000000000................
⋯25 more rows
Execute shell command (ShellExecuteA) 0xa36d4–0xa3934
⋯14 more rows
0xa37b400000000000000000000000000000000................
0xa37c400000000000000000000000000000000................
0xa37d400000000000000000000000000000000................
0xa37e400000000000000000000000000000000................
0xa37f400000000000000000000000000000000................
⋯9 more rows
0xa389400000000000000000000000000000000................
0xa38a400000000000000000000000000000000................
0xa38b400000000000000000000000000000000................
0xa38c400000000000000000000000000000000................
⋯7 more rows
Query/set system parameters (string) 0xc2176–0xc2216
0xc217673736167650000005472616e736c6174ssage...Translat
0xc2186654d4449537973416363656c00000054eMDISysAccel...T
0xc21967261636b506f7075704d656e75000000rackPopupMenu...
0xc21a653797374656d506172616d6574657273SystemParameters
0xc21b6496e666f4100000053686f7757696e64InfoA...ShowWind
0xc21c66f7700000053686f775363726f6c6c42ow...ShowScrollB
⋯5 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.