Benign Download

Trojan-GameThief.Win32.OnLineGames.wqu

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256835088ae750db9fa6f230bbcc409f2c9582a9922f0722f848268b3942a47524a
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x19cc–0x1aac
⋯3 more rows
0x19fc00000000000000000000000001000000................
0x1a0cfae6e6e2a8bdbde8e6e6bca4a3a3a1ab................
0x1a1cbcf1fdffbde5fefebdfefbfcbcf3e1e2................
0x1a2c00000000000000000000000000000000................
0x1a3c00000000000000000000000000000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.