Benign Download

Trojan-GameThief.Win32.OnLineGames.jls

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-25652f1aeb6ff67a998b75af1b896bc3caa9087de3a8727956458c460a81c0b5c9d
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x58ac–0x59dc
⋯3 more rows
0x58dc8bec83ec1453565764a1180000000000.....SVWd.......
0x58ecfce0e0e4aebbbbe3e3e3bafafde1f0e2................
0x58fcf0baf7fbf9bbedfdfafce1f5faf3bbf8................
0x590cfdfabaf5e7e400008bc88d71018a1141...........q...A
0x591c3ad375f92bce5150b90000008d888825:.u.+.QP.......%
0x592c000089b083c010508d4dac0057ff750c.......P.M..W.u.
0x593c8bfeff7508000000fce0e0e4aebbbbe3...u............
0x594ce3e3bafafde1f0e2f0baf7fbf9bbf3f5................
0x595cfaf5bbf8fdfabaf5e7e40000b1e7abf5................
0x596ca9b1e7b2e7a9b1e7b2e1a9b1e7b2e4a9................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.