Benign Download

Trojan.Win32.Buzus.nlp

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256861d8ab2c626947cc88a88705305c72322b433f2eed38cad2c45dd230eb3dd79
MaleculeMdTh

Evidence

Encoded content decoded: xor 0xd9c0–0xdad0
⋯3 more rows
0xd9f05850414444494e4750414444494e4758XPADDINGPADDINGX
0xda0085868a888581869a9d95d8d8dfde9588................
0xda108580c78c918c9592abdfa8d1d9dea7df................
0xda20c4dddbadafc4ddbed9dbc4d0daacdcc4................
0xda30abd8dcdfabdaafa8d1a8a5d89495ab88................
0xda40878d86868295ab88878d868682c9af86................
0xda50858d8c9b95908c9a95908c9a95819d9d................
0xda6099d3c6c69e9e9ec7dbd1df8188829d86................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.