Benign Download

Trojan-PSW.Win32.Delf.jw

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256600967cc912ec5010266eca834d2fb4356334ce237f7b39a47a1f1e2b9e8e6f6
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x55a8–0x5688
⋯3 more rows
0x55d8ecaee4ecec000000ffffffff2d000000............-...
0x55e8d3efe6f4f7e1f2e5dccde9e3f2eff3ef................
0x55f8e6f4dcd7e9eee4eff7f3dcc3f5f2f2e5................
0x5608eef4d6e5f2f3e9efeedcd2f5ee000000................
0x5618ffffffff02000000f2f80000ffffffff................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.