Hostile 92% Download

Backdoor.Win32.Agent.wjl

Named backdoor, malware signature match

Detects malware from disclosed CN malware setPercent-encoded content decoded
SHA-2562e94fdccef3d23d9f285ce72f77428fbfe5fafb7182a06c09fefc1e777083847
MaleculeMdTh

Evidence

Percent-encoded content decoded 0x6482–0x6712
⋯7 more rows
0x64f27a69702c206465666c61746500000d0azip, deflate....
0x6502557365722d4167656e743a4d6f7a696cUser-Agent:Mozil
0x65126c612f342e302028636f6d7061746962la/4.0 (compatib
0x65226c653b204d53494520362e303b205769le; MSIE 6.0; Wi
0x65326e646f7773204e5420352e313b205356ndows NT 5.1; SV
0x65423129000000000d0a436f6e6e656374691)......Connecti
0x65526f6e3a204b6565702d416c6976650000on: Keep-Alive..
⋯15 more rows
0x66522d63616368650d0a0000470000000d0a-cache....G.....
0x6662486f73743a2000000000436f6f6b6965Host: ....Cookie
0x66723a2067657475726c3d253246696e6465: geturl=%2Finde
0x6682782532456173702533463b204476466fx%2Easp%3F; DvFo
0x669272756d2b382532453225354662627325rum+8%2E2%5Fbbs%
0x66a2324564766262732532456e65743d53742Edvbbs%2Enet=St
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.