Trojan-Spy.Win32.Goldun.apx
Detects an XORed URL in an executableEmbedded PE binary at file offset 0x1070 (~77839 bytes)
SHA-25649f4da605258e7b562ebb870be5b7a905371c1d09bc8b371cbf448a8bc37be82
MaleculeMdTh
Evidence
⋯3 more rows
0x106041005200590000000000000000000000A.R.Y...........
0x10704d5a90000300000004000000ffff0000MZ..............
0x1080b8000000000000004000000000000000........@.......
0x109000000000000000000000000000000000................
⋯7 more rows
⋯3 more rows
0x10b000d0a0000526566657265723a20000000....Referer: ...
0x10b10687474703a2f2f0068747470733a2f2fhttp://.https://
0x10b20000000003a2f2f000d0a0000436f6e74....://.....Cont
⋯7 more rows
⋯3 more rows
0x1400eb8babcb9b8f2b4b3b9b8a5f3adb5addd................
0x1401eb5a9a9ade7f2f2b1b2bebcb1b5b2aea9................
0x1402ef28fb8b3b8babcb9b8f2b4b3bbb2f3a9................
0x1403ea5a9ddb5a9a9ade7f2f2b1b2bebcb1b5................
0x1404eb2aea9f28fb8b3b8babcb9b8f2adafb2................
0x1405ea9b8bea9f3b8a5b8ddbfbcbeb69db0bc................
0x1406eb4b1f3beb2b0dde9ededdde6dd7b0000.............{..
0x1407e00 .