A forum for reverse engineering, OS internals and malware analysis 

Ask your beginner questions here.
 #31559  by EP_X0FF
 Sat May 05, 2018 5:03 am
It is trojan downloader.

Obfuscated strings from inside.
Code: Select all
"Software\\Microsoft"
"\\Windows\\Currentversion\\Run"
"Taskhst"
"Environment"
"Cq"
"cmd /c start %Cq% "
"&& exit"
"ntuser"
"toolsd.exe"
"aday.primeservices.mobi"
"/IXR/goprim.php"
"Connection: keep-alive"
"Content-type: application/x-www-form-urlencoded"