Benign Download

Trojan-Downloader.Win32.Zlob.erm

Detects an XORed URL in an executable
SHA-25645ad768f3c73bda6b52b362dca13e9ca1e24171bde1d9d6abfe8aae38b97096d
MaleculeTh

Evidence

Detects an XORed URL in an executable 0x2838–0x28f8
⋯3 more rows
0x2868fef5b3edf5eda2ececa0b8ee00000000................
0x2878e2fefefab0a5a5ebf9ebeceffef3fdeb................
0x2888f8e4e3e4eda4e9e5e7a500006578706c............expl
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.