Benign Download

Trojan-Dropper.Win32.Agent.hd

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-2560e4e32dcdd485665c00c3509c1870e7dc310cd559bbdeb21ca457ec48ef38c24
MaleculeMdTh

Evidence

Encoded content decoded: xor → base64 0x12c48–0x12d18
⋯3 more rows
0x12c7800000000000000000000000000000000................
0x12c8820002000200020002000200020002000 . . . . . . . .
0x12c9820002800280028002800280020002000 .(.(.(.(.(. . .
0x12ca820002000200020002000200020002000 . . . . . . . .
⋯7 more rows
Encoded content decoded: xor 0x13c14–0x13cf4
⋯3 more rows
0x13c4461646974696f6e616c20536f72740000aditional Sort..
0x13c540c0c1a0c071036040c082d0403040c10......6...-.....
0x13c6410081d080c3e410055534100043e4100.....>A.USA..>A.
0x13c7447425200fc3d410043484e00f43d4100GBR..=A.CHN..=A.
0x13c84435a4500ec3d410047425200dc3d4100CZE..=A.GBR..=A.
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.