Benign Download

Trojan-GameThief.Win32.Nilage.ph

Detects an XORed URL in an executable
SHA-25648b49beeb71b607b0f1a8bcbe585dbb79a2eb257069c5989ef1c44f28fe92ad8
MaleculeTh

Evidence

Detects an XORed URL in an executable 0x5834–0x58f4
⋯3 more rows
0x58641ccdffffc3e906c7ffffebeb8be55dc3..............].
0x5874e8f4f4f0baafaff7f7f7aee7e1ede5e1................
0x5884eee1e9aee3efedafece9eee5e1e7e5b2................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.