Benign Download

Trojan-GameThief.Win32.OnLineGames.ssl

Detects an XORed URL in an executable
SHA-2567cb70155de7d91ea329143b29456473d64fc514aa469fe86bb13ba1b9cc6c878
MaleculeTh

Evidence

Detects an XORed URL in an executable 0x50f0–0x51b0
⋯3 more rows
0x51206368646c6f67696e0000000000000000chdlogin........
0x51305b474743091c1c5947021d405c465959[GGC...YG..@\FYY
0x514059591d505c5e1c50505b5b1c5f5a5d1dYY.P\^.PP[[._Z].
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.