Benign Download

Trojan-GameThief.Win32.Nilage.hp

Detects Pirpi Backdoor - and other malware (generic rule)Detects an XORed URL in an executable
SHA-2566e0d1fdb6a878d40bf6fb7201d07803223b997f5971f000ba9f03ea19a661f36
MaleculeMdTh

Evidence

Detects an XORed URL in an executable 0x4120–0x41e0
⋯3 more rows
0x4150eb5f5e5b8be55dc3ffffffff07000000._^[..].........
0x4160687474703a2f2f00ffffffff01000000http://.........
0x41702f000000558bec81c4c8fbffff535633/...U........SV3
⋯7 more rows
Encoded content decoded: xor 0x55a0–0x5680
⋯3 more rows
0x55d0eb8be55dc3000000ffffffff2d000000...]........-...
0x55e05f434a585b4d5e495041656f7e637f63_CJX[M^IPAeo~c.c
0x55f06a78505b656268637b7f504f797e7e69jxP[ebhc{.POy~~i
0x560062785a697e7f656362505e7962000000bxZi~.ecbP^yb...
0x561053484f5754494d4500000000558becb9SHOWTIME....U...
⋯7 more rows
Embedded PE binary at file offset 0xd0f0 (~110592 bytes) 0xd0b0–0xd180
⋯3 more rows
0xd0e04b0041004700450049004e0046004f00K.A.G.E.I.N.F.O.
0xd0f04d5a40000100000002000000ffff0000MZ@.............
0xd10000020000000000004000000000000000........@.......
0xd11000000000000000000000000000000000................
⋯7 more rows
Detects Pirpi Backdoor - and other malware (generic rule) 0xf38f–0xf52f
⋯7 more rows
0xf3ffcccce9db00000051568b753c8b742e78.......QV.u<.t.x
0xf40f03f5568b762003f533c94941ad03c533..V.v ..3.IA...3
0xf41fdb0fbe103ad67408c1cb0d03da40ebf1....:.t......@..
0xf42f3b1f75e75e8b5e2403dd668b0c4b8b5e;.u.^.^$..f..K.^
0xf43f1c03dd8b048b03c5ab5e59c3e8c8feff.........^Y.....
⋯15 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.