Benign Download

Trojan-GameThief.Win32.OnLineGames.aoq

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256735562fb1c0bdd1542dce763cc58e8e3263c8d2b4e0513916bbc398c7a3c7929
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x17cc–0x18ac
⋯3 more rows
0x17fc00000000000000000000000001000000................
0x180cfee2e2e6acb9b9e1f9f9fab8fef9e5e2................
0x181ca2b8e2f0fff2f5b8f5f9fbb9fbf9efe3................
0x182cb9fafff8b8f7e5e60000000000000000................
0x183c00000000000000000000000000000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.