Benign Download

Trojan-GameThief.Win32.OnLineGames.eqk

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-2565ccb767b33ece8b766141894c82db00c3a87c301321dff878e1f9f2fc5cc57a3
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x4a4c–0x4c3c
⋯3 more rows
0x4a7cd872000053756e67616d652e65786500.r..Sungame.exe.
0x4a8c99858581cbdede9b85c3df829e849b9b................
0x4a9c9b9bdf929e9cde9b9b9b85de9d989fdf................
0x4aac908281008bc88d71018a11413ad375f9.......q...A:.u.
0x4abc2bce5150b90000008d881c20000089b0+.QP....... ....
⋯6 more rows
0x4b2c7f88465bc685e3dfffff01c645fc0000..F[........E...
0x4b3c5068010050048b1599858581cbdede9bPh..P...........
0x4b4c85c0df829e849b9b9b9bdf929e9cde92................
0x4b5c929999de9d989fdf908281006368646c............chdl
0x4b6c6f67696e0000000000000000c680bc00ogin............
0x4b7c000000008bc88d79018d642400000000.......y..d$....
0x4b8c8b406005b40600008d85d04100000000.@`........A....
0x4b9c99858581cbdede9788c0df829e849b9b................
0x4bac9b9bdf929e9cde9b9b9788de9d989fdf................
0x4bbc90828100d482ce90ccd482d782ccd482................
0x4bccd784ccd482d781ccd482d78281ccd482................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.