Benign Download

Trojan-PSW.Win32.Delf.os

Detects an XORed URL in an executableEmbedded PE binary at file offset 0xa508 (~88824 bytes)
SHA-25676d943d5bd76b3d543d466d34ea2e8ccfb9f3ee1753ea7838eb84c1b94dd6255
MaleculeMdTh

Evidence

Detects an XORed URL in an executable 0x339c–0x345c
⋯3 more rows
0x33cc90efffffc3e902eaffffebde8be55dc3..............].
0x33dc687474703a2f2f736e2e747761766769http://sn.twavgi
0x33ec726c2e636f6d2f736e2e6173703f746frl.com/sn.asp?to
⋯7 more rows
Embedded PE binary at file offset 0xa508 (~88824 bytes) 0xa4c8–0xa598
⋯3 more rows
0xa4f84b0041004700450049004e0046004f00K.A.G.E.I.N.F.O.
0xa5084d5a50000200000004000f00ffff0000MZP.............
0xa518b80000000000000040001a0000000000........@.......
0xa52800000000000000000000000000000000................
⋯7 more rows
Encoded content decoded: xor 0x19640–0x19720
⋯3 more rows
0x19670ffebf0595dc30000ffffffff33000000...Y].......3...
0x19680e8f4f4f0baafaff7e5e2e1f0f0aee3e8................
0x19690e9eee1e7e1ede5f3aeeee5f4afedefee................
0x196a0e5f9aff3e1e6e5e2eff8afeff5f4aee1................
0x196b0f3f0f800558bec51817d0c0102000074....U..Q.}.....t
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.