Benign Download

IM-Worm.Win32.Lewor.c

Detects an XORed URL in an executable
SHA-256884ddcc94aad365337ef64ef8a033de952a14fea8fb360d663aad7a6995550b6
MaleculeTh

Evidence

Detects an XORed URL in an executable 0x35dd–0x369d
⋯3 more rows
0x360dd7cbc0baf0c8d4b3c22ac2e5b9b2b9b2.........*......
0x361d6e7272763c2929717171286c697f6f63nrrv<))qqq(li.oc
0x362d7e2865696b2967646528637e63ccd5c0~(eik)gde(c~c...
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.