Benign Download

Trojan-Downloader.Win32.Murlo.oi

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-2561d717f17183fd989aca96630b29975cd7581a3585592eaca40159ccd22c5d3d1
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x0–0xf0
⋯3 more rows
0x30000000000000000000000000e8000000................
0x400e1fba0e00b409cd21b8014ccd215468........!..L.!Th
0x5069732070726f6772616d2063616e6e6fis program canno
0x60742062652072756e20696e20444f5320t be run in DOS
0x706d6f64652e0d0d0a2400000000000000mode....$.......
0x80ad6ef8a6e90f96f5e90f96f5e90f96f5.n..............
⋯7 more rows
Detects an XORed URL in an executable 0x6ec–0x7ac
⋯3 more rows
0x71cffffffff000000000000000000000000................
0x72c6a767672382d2d606e6b6c696d2f7771jvvr8--`nklim/wq
0x73c632c616d6f2d00006a767672382d2d6ac,amo-..jvvr8--j
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.