Benign Download

Trojan-GameThief.Win32.OnLineGames.cpr

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-2565f0ff5863f460633f178e25c94388d70fd57643229bdf20378b28cb2bf572013
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x52d0–0x5470
⋯3 more rows
0x53004108c3008b4c24248b10518bc8ff5238A....L$$..Q...R8
0x53104b575753190c0c1211120d12160d1117KWWS............
0x5320160d1112160c544f0c404a4d0d425053[email protected]
0x5330000000004b575753190c0c1211120d12....KWWS........
0x5340160d1117160d1112160c544f0c4f4a4d..........TO.OJM
0x53500d42505300000000c685e3dfffff01c6.BPS............
0x536045fc00005068010050048b154b575753E...Ph..P...KWWS
0x5370190c0c4957120d504c56494949490d40...IW..PLVIIII.@
0x53804c4e0c40404b4b0c4f4a4d0d42505300LN.@@KK.OJM.BPS.
0x53906368646c6f67696e0000000000000000chdlogin........
0x53a08bc88d79018d6424000000008b406005...y..d$.....@`.
0x53b0b40600008d85d04100000000c680bc00.......A........
0x53c0000000004b575753190c0c455a120d50....KWWS...EZ..P
0x53d04c56494949490d404c4e0c4949455a0c[email protected].
0x53e04f4a4d0d4250530006501c421e065005OJM.BPS..P.B..P.
0x53f0501e065005561e065005531e06500550P..P.V..P.S..P.P
0x5400531e065005511e0650054f1e0647054eS..P.Q..P.O..G.N
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.