Benign Download

Trojan-Spy.Win32.Delf.nl

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256230f863f957c7aac2d28d15d380680ea7a8c13a75431d5708689823061e2b04d
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x6198–0x61f8
⋯3 more rows
0x61c8634164647265737300d5eecbeeeff78dcAddress........
0x61d8e8f4f4f0baafaff7f7f7aef3f5eee8e1................
0x61e8e3ebaee3eeafe3f3aff3e5eee4ede1e9................
0x61f8ecaee1f3f08d2d000000 ......-...

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.