Benign Download

Trojan-GameThief.Win32.Magania.be

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-2567c295a4d73c6e0fccee1a6dcf8c23e623c35b36c6ac5df3f2d66943ac43dacd7
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x56b0–0x5790
⋯3 more rows
0x56e0636c617373000000ffffffff2d000000class.......-...
0x56f0d3efe6f4f7e1f2e5dccde9e3f2eff3ef................
0x5700e6f4dcd7e9eee4eff7f3dcc3f5f2f2e5................
0x5710eef4d6e5f2f3e9efeedcd2f5ee000000................
0x5720ffffffff0e000000e3badce7e1ede5e1................
⋯7 more rows
Detects an XORed URL in an executable 0x140b0–0x14170
⋯3 more rows
0x140e04f4e2e444c4c0000ffffffff29000000ON.DLL......)...
0x140f068747470733a2f2f676f6f646c6f636bhttps://goodlock
0x141002e67616d616e69612e636f6d2f53686f.gamania.com/Sho
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.