Benign Download

Trojan-Downloader.Win32.Dadobra.aa

Image list icon size importExecute shell command (ShellExecuteA)
SHA-256ddc78701bb32d7140a073acdff1fea66b3c6177de28ce8e6492b6d8c3cf9e0a5
MaleculeH₂(PoU)

Evidence

Query/set system parameters (string) 0x50b4c–0x50bec
0x50b4c654d65737361676500005472616e736ceMessage..Transl
0x50b5c6174654d4449537973416363656c0000ateMDISysAccel..
0x50b6c547261636b506f7075704d656e750000TrackPopupMenu..
0x50b7c53797374656d506172616d6574657273SystemParameters
0x50b8c496e666f4100000053686f7757696e64InfoA...ShowWind
0x50b9c6f77000053686f775363726f6c6c4261ow..ShowScrollBa
⋯5 more rows
Query/set system parameters (symbol) 0x52410–0x525c0
0x5241000000000000000000000000000000000................
0x5242000000000000000000000000000000000................
0x5243000000000000000000000000000000000................
0x5244000000000000000000000000000000000................
0x5245000000000000000000000000000000000................
⋯23 more rows
Execute shell command (ShellExecuteA) 0x525dc–0x5279c
⋯12 more rows
0x5269c00000000000000000000000000000000................
0x526ac00000000000000000000000000000000................
0x526bc00000000000000000000000000000000................
0x526cc00000000000000000000000000000000................
0x526dc00000000000000000000000000000000................
0x526ec00000000000000000000000000000000................
0x526fc00000000000000000000000000000000................
0x5270c00000000000000000000000000000000................
0x5271c00000000000000000000000000000000................
0x5272c00000000000000000000000000000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.