Benign Download

Trojan-GameThief.Win32.Nilage.afz

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-25613b645716b1eea4b26cfc314eb2d3e1cd23a408ddf8eb1b6b24a3f0baadb7827
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x56dc–0x57bc
⋯3 more rows
0x570c2e2e2e2e2e000000ffffffff2d000000............-...
0x571cd3efe6f4f7e1f2e5dccde9e3f2eff3ef................
0x572ce6f4dcd7e9eee4eff7f3dcc3f5f2f2e5................
0x573ceef4d6e5f2f3e9efeedcd2f5ee000000................
0x574cffffffff07000000e3badce7e1ede500................
⋯7 more rows
Detects an XORed URL in an executable 0x11524–0x115e4
⋯3 more rows
0x11554e8f4f4f0baafaf00ffffffff08000000................
0x11564e8f4f4f0f3baafaf00000000ffffffff................
0x11574020000000d0a0000ffffffff06000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.