Benign Download

Trojan-GameThief.Win32.OnLineGames.kcs

Detects an XORed URL in an executableEmbedded PE binary at file offset 0x4940 (~123584 bytes)
SHA-25653bbb86789c96a86471eeb27b5157e89bc94ad60ae90804e5e3eb2d702c1efc8
MaleculeMdTh

Evidence

Embedded PE binary at file offset 0x4940 (~123584 bytes) 0x4900–0x49d0
⋯3 more rows
0x49306974000c4b57696e646f777300000000it..KWindows....
0x49404d5a50000200000004000f00ffff0000MZP.............
0x4950b80000000000000040001a0000000000........@.......
0x496000000000000000000000000000000000................
⋯7 more rows
Detects an XORed URL in an executable 0x9ab4–0x9b74
⋯3 more rows
0x9ae4eb5f5e5b8be55dc3ffffffff07000000._^[..].........
0x9af4687474703a2f2f00ffffffff01000000http://.........
0x9b042f000000558bec81c4b8fbffff535657/...U........SVW
⋯7 more rows
Encoded content decoded: xor 0x19694–0x19984
⋯3 more rows
0x196c46959575300000000ffffffff1e000000iYWS............
0x196d4e8f4f4f0baafaff4f7aee7e1f3e8e3e1................
0x196e4f2e4aee7e1ede1eee9e1aee3efed0000................
0x196f4ffffffff1f000000e8f4f4f0baafaff4................
0x19704f7aee7e1f3e8e3e1f2e4aee7e1ede1ee................
0x19714e9e1aee3efedaf00ffffffff28000000............(...
0x19724e8f4f4f0baafaff4f7aee7e1f3e8e3e1................
0x19734f2e4aee7e1ede1eee9e1aee3efedafe9................
0x19744eee4e5f8aee1f3f000000000ffffffff................
0x197542a000000e8f4f4f0f3baafaff4f7aee7*...............
0x19764e1f3e8aee7e1ede1eee9e1aee3efedaf................
0x19774c7c1d3c8ccefe7e9eeaee1f3f0f80000................
0x19784ffffffff1b000000e8f4f4f0f3baafaf................
0x19794f4f7aee7e1f3e8aee7e1ede1eee9e1ae................
0x197a4e3efed00ffffffff1c000000e8f4f4f0................
0x197b4f3baafaff4f7aee7e1f3e8aee7e1ede1................
0x197c4eee9e1aee3efedaf00000000ffffffff................
0x197d42a000000e8f4f4f0f3baafaff4f7aee7*...............
0x197e4efefe4ecefe3ebaee7e1ede1eee9e1ae................
0x197f4e3efedafe9eee4e5f8aee1f3f0f80000................
0x19804ffffffff2a000000e8f4f4f0f3baafaf....*...........
0x19814f4f7aee7efefe4ecefe3ebaee7e1ede1................
0x19824eee9e1aee3efedafc9eee4e5f8aee1f3................
0x19834f0f80000ffffffff2b000000e8f4f4f0........+.......
0x19844baafaff4f7aee7e1ede1eee9e1aee3ef................
0x19854edafc7c8cfcdc5afc8efede5dfc3e5ee................
0x19864f4e5f2aec1d3d000ffffffff16000000................
0x19874e8f4f4f0baafaff4f7aee7e1ede1eee9................
0x19884e1aee3efedaf0000ffffffff15000000................
0x19894e8f4f4f0baafaff4f7aee7e1ede1eee9................
0x198a4e1aee3efed000000ffffffff2e000000................
0x198b4e8f4f4f0baafaff4f7aee7e1ede1eee9................
0x198c4e1aee3efedafe4e5e6e1f5ecf4aee1f3................
0x198d4f0bff5f3e5f2dfecefe3e1f4e5bd0000................
0x198e4ffffffff26000000e8f4f4f0f3baafaf....&...........
0x198f4f4f7aee7e1f3e8aee7e1ede1eee9e1ae................
0x19904e3efedafc2ece1eeebaee1f3f0f80000................
0x19914ffffffff28000000e8f4f4f0baafaff4....(...........
0x19924f7aee7e1f3e8e3e1f2e4aee7e1ede1ee................
0x19934e9e1aee3efedaff3f0e1e3e5aee8f4ed................
0x1994400000000ffffffff1f000000e8f4f4f0................
0x19954f3baafaff4f7aee7efefe4ecefe3ebae................
⋯3 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.