Benign Download

Trojan-GameThief.Win32.OnLineGames.ehf

Detects an XORed URL in an executable
SHA-2567a01f7e8da5a8b424fec57da4bfc27fef09ed7946815045977348777664bfebf
MaleculeTh

Evidence

Detects an XORed URL in an executable 0x52d0–0x5390
⋯3 more rows
0x5300b2b4000010720000ac710000d8720000.....r...q...r..
0x5310405c5c58120707425c1a065b475d4242@\\X...B\..[G]BB
0x53204242064b4745074242425c0744414606BB.KGE.BBB\.DAF.
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.