Trojan-GameThief.Win32.Lmir.zp
Detects an XORed URL in an executableEmbedded PE binary at file offset 0x5bb8 (~231028 bytes)
SHA-2568322b4d6d250c2ad610cc81739201af29362e2d5378842f736936a1ef6caa4f8
MaleculeTh
Evidence
⋯3 more rows
0x5ba84d00410049004e00490043004f004e00M.A.I.N.I.C.O.N.
0x5bb84d5a50000200000004000f00ffff0000MZP.............
0x5bc8b80000000000000040001a0000000000........@.......
0x5bd800000000000000000000000000000000................
⋯7 more rows
⋯3 more rows
0x13ab0eb5f5e5b8be55dc3ffffffff07000000._^[..].........
0x13ac0687474703a2f2f00ffffffff01000000http://.........
0x13ad02f000000558bec81c4c8fbffff535633/...U........SV3
⋯7 more rows