Benign Download

Backdoor.Win32.Bandok.ej

Detects an XORed URL in an executable
SHA-2568476a8903372220315a1000628415a445775c5d6af043e0b8e57cecb64ce6ccc
MaleculeTh

Evidence

Detects an XORed URL in an executable 0x7a99–0x7b59
⋯3 more rows
0x7ac93c3e6e69454da5a5a7a56a6a3e3d6226<>niEM....jj>=b&
0x7ad9dbc7c7c3899c9cc45b9ddfdcc5d69dd0........[.......
0x7ae9dcde9cc0d6c7c7cbfbcaa5daddd4c09d................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.