Trojan-PSW.Win32.Delf.nh
Detects an XORed URL in an executableEmbedded PE binary at file offset 0x79ac (~125524 bytes)
SHA-2562c873f2dae5c1acdb5601814f8943442737032fafc70971123745cbd06b1440d
MaleculeMdTh
Evidence
⋯3 more rows
0x3d68010000005c000000ffffffff2d000000....\.......-...
0x3d78d3efe6f4f7e1f2e5dccde9e3f2eff3ef................
0x3d88e6f4dcd7e9eee4eff7f3dcc3f5f2f2e5................
0x3d98eef4d6e5f2f3e9efeedcd2f5ee000000................
0x3da8558bec81c4dcfdffff53568bf28bd833U........SV....3
⋯7 more rows
⋯3 more rows
0x799c410049004e00490043004f004e000000A.I.N.I.C.O.N...
0x79ac4d5a50000200000004000f00ffff0000MZP.............
0x79bcb80000000000000040001a0000000000........@.......
0x79cc00000000000000000000000000000000................
⋯7 more rows
⋯3 more rows
0x3d68010000005c000000ffffffff2d000000....\.......-...
0x3d78d3efe6f4f7e1f2e5dccde9e3f2eff3ef................
0x3d88e6f4dcd7e9eee4eff7f3dcc3f5f2f2e5................
0x3d98eef4d6e5f2f3e9efeedcd2f5ee000000................
0x3da8558bec81c4dcfdffff53568bf28bd833U........SV....3
⋯7 more rows
⋯3 more rows
0x799c410049004e00490043004f004e000000A.I.N.I.C.O.N...
0x79ac4d5a50000200000004000f00ffff0000MZP.............
0x79bcb80000000000000040001a0000000000........@.......
0x79cc00000000000000000000000000000000................
⋯7 more rows
⋯3 more rows
0x136c48a3e00c04fc9e26effffffff28000000.>..O..n....(...
0x136d4e8f4f4f0baafaff7f7f7aef7e1f9e9ae................
0x136e4e3efedaef4f7afe8eff4afd3f4e1f2f4................
⋯7 more rows