Benign Download

Trojan-GameThief.Win32.OnLineGames.ydq

Detects an XORed URL in an executable
SHA-25615cd2f17fa75bb50e6dca9e6db94c46acd361a5906e3dac3fe96393f8162440b
MaleculeTh

Evidence

Detects an XORed URL in an executable 0x1d70–0x1e30
⋯3 more rows
0x1da0898540ffffff8b0d5068010050048b0d[email protected]...
0x1db05d4141450f1a1a5f41041b465a405f5f]AAE..._A..FZ@__
0x1dc05f5f1b565a581a56565d5d1a595c5b1b__.VZX.VV]].Y\[.
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.