Benign Download

Trojan-GameThief.Win32.OnLineGames.pki

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-2562dbc9bd64070b5edb88bcb63a2e0b6da4ccc1444ad9dcdbaad5169fd86f43b6c
MaleculeMdTh

Evidence

Detects an XORed URL in an executable 0x5620–0x56e0
⋯3 more rows
0x56505e5b595dc3000000ffffffff07000000^[Y]............
0x5660687474703a2f2f00ffffffff01000000http://.........
0x56702f000000558bec8b45088b40fc50e849/[email protected]
⋯7 more rows
Encoded content decoded: xor 0x159e7–0x15ac7
⋯3 more rows
0x15a1734e834ec34f034f434f834fc340035044.4.4.4.4.4.4.5.
0x15a273508350c351035143518351c352035245.5.5.5.5.5.5 5$
0x15a373528352c3530350000000000000000005(5,505.........
0x15a4700000000000000000000000000000000................
0x15a5700000000000000000000000000000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.