Benign 38% Download

Backdoor.Win32.Bifrose.thc

Detects Base64 encoded Executable in ExecutableEmbedded PE binary at file offset 0x76a6a (~9729 bytes)
SHA-2567fd1d09a4db61516454e11d886ba46671641fdb637e66c379fedf722d6e09ffa
MaleculeTh

Evidence

Embedded PE binary at file offset 0x76a6a (~9729 bytes) 0x769ea–0x76b7a
⋯7 more rows
0x76a5a202020202020202020207c2d2d7c317c |--|1|
0x76a6a5456715141414d414141414541414141TVqQAAMAAAAEAAAA
0x76a7a2f2f3841414c67414141414141414141//8AALgAAAAAAAAA
0x76a8a51414141414141414141414141414141QAAAAAAAAAAAAAAA
⋯15 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.