Benign Download

Trojan-GameThief.Win32.MFirst.eu

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-25620b9514e7fd766765f32d32aefa3a332171cd7b43e03aebb7f6ec1e2db2ca7bb
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x91d2–0x92b2
⋯3 more rows
0x920200000000000000000000002d000000df...........-....
0x9212b7ababafe5f0f0a8a8a8f1b1b6aab5b6................
0x9222baadf1bcb0b2f0aba7a5b0b1b8f0afb0................
0x9232acabb3a6f0afb0acabf1beacaf000000................
0x924200000000000000000000000000000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.