Trojan-PSW.Win32.Element.ab
Detects an XORed URL in an executableEmbedded PE binary at file offset 0xb0f0 (~49152 bytes)
SHA-2569207ec8ae3c2329fa21a0f3492724872bc6f9cb6207029b73ef4962da87902de
MaleculeMdTh
Evidence
⋯3 more rows
0xb0e041004700450049004e0046004f000000A.G.E.I.N.F.O...
0xb0f04d5a50000200000004000f00ffff0000MZP.............
0xb100b80000000000000040001a0000000000........@.......
0xb11000000000000000000000000000000000................
⋯7 more rows
⋯3 more rows
0xf1e0f08bc35e5b595dc3ffffffff07000000...^[Y].........
0xf1f0687474703a2f2f00ffffffff01000000http://.........
0xf2007b000000ffffffff010000007d000000{...........}...
⋯7 more rows
⋯3 more rows
0x1aff000000000000000000000000000000000................
0x1b0006478787c3623237d7d22393e3c7f6a22dxx|6##}}"9><.j"
0x1b010637e6b2368637b622368637b62227874c~k#hc{b#hc{b"xt
0x1b020782a4f7a614d x*OzaM