Benign Download

Trojan.Win32.Buzus.ubm

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-2561422e55755871cbdd2543de43798b382b035fbcb41de2ee1b0e19bf0c0ca6058
MaleculeMdTh

Evidence

Encoded content decoded: xor 0xd9c0–0xdad0
⋯3 more rows
0xd9f05850414444494e4750414444494e4758XPADDINGPADDINGX
0xda00d8dbdec7d9c7d9c7d895d8d8dfde9588................
0xda108580c78c918c9592abdfa8d1d9dea7df................
0xda20c4dddbadafc4ddbed9dbc4d0daacdcc4................
0xda30abd8dcdfabdaafa8d1a8a5d89495ab88................
0xda40878d86868295ab88878d868682c9af86................
0xda50858d8c9b95878695878695819d9d99d3................
0xda60c6c69e9e9ec7dbd1df8188829d868685................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.