Benign Download

Trojan-GameThief.Win32.OnLineGames.yad

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-25647bade1167569ac80f48096420e8314b00d2a371970c6c34870bf0326e75a087
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x3f8c–0x410c
⋯3 more rows
0x3fbcceeec1e1c0e0c3e3c6b4b7b7b7b7b4b4................
0x3fccdcc0c0c48e9b9bd2cd869ac7dbc1dede................
0x3fdcdede9ad7dbd99bdeded2cd9bd8ddda9a................
0x3fecd5c7c4004c6f61644c69627261727945....LoadLibraryE
0x3ffc78570000c8a1cffb0000000042000000xW..........B...
⋯5 more rows
0x405c00000000000000000000000001960000................
0x406cfee2e2e6acb9b9e1e1e1b8e5e3e6f3e4................
0x407ce2f7f8f1f9b8f8f3e2b9f4f7f9f4f7f9................
0x408cb9fafff8b8f7e5e60000000000000000................
0x409c00000000000000000000000000000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.