Benign Download

Trojan-GameThief.Win32.Nilage.adv

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-2565ad1a54b3687aaadc96ac3b3faead55dd51a971c885df4d9e4cd77e474d2c336
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x3d04–0x3de4
⋯3 more rows
0x3d3403000000e1e2b100ffffffff2d000000............-...
0x3d44d3efe6f4f7e1f2e5dccde9e3f2eff3ef................
0x3d54e6f4dcd7e9eee4eff7f3dcc3f5f2f2e5................
0x3d64eef4d6e5f2f3e9efeedcd2f5ee000000................
0x3d74ffffffff07000000e3badce7e1ede500................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.