Benign Download

Trojan-GameThief.Win32.MultiFirst.cn

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-25624def6a2d0c7cb56d0ee0b42d62336c9d48b86ece5398c97ef4b76d1de812d72
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x80b6–0x8196
⋯3 more rows
0x80e6c39594d18bc99f9e9400002800000074...........(...t
0x80f61c0000044e5b5b101c465a1517414142....N[[..FZ..AAB
0x8106425a171a5b2e3b3a332c2c2c3b21205bBZ..[.;:3,,,;! [
0x8116041b07005a1507040000000000000000....Z...........
0x812600000000000000000000000000000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.