Benign Download

Trojan-PSW.Win32.Element.ab

Detects an XORed URL in an executableEmbedded PE binary at file offset 0xb0f0 (~49152 bytes)
SHA-2569207ec8ae3c2329fa21a0f3492724872bc6f9cb6207029b73ef4962da87902de
MaleculeMdTh

Evidence

Embedded PE binary at file offset 0xb0f0 (~49152 bytes) 0xb0b0–0xb180
⋯3 more rows
0xb0e041004700450049004e0046004f000000A.G.E.I.N.F.O...
0xb0f04d5a50000200000004000f00ffff0000MZP.............
0xb100b80000000000000040001a0000000000........@.......
0xb11000000000000000000000000000000000................
⋯7 more rows
Detects an XORed URL in an executable 0xf1b0–0xf270
⋯3 more rows
0xf1e0f08bc35e5b595dc3ffffffff07000000...^[Y].........
0xf1f0687474703a2f2f00ffffffff01000000http://.........
0xf2007b000000ffffffff010000007d000000{...........}...
⋯7 more rows
Encoded content decoded: xor 0x1afc0–0x1b020
⋯3 more rows
0x1aff000000000000000000000000000000000................
0x1b0006478787c3623237d7d22393e3c7f6a22dxx|6##}}"9><.j"
0x1b010637e6b2368637b622368637b62227874c~k#hc{b#hc{b"xt
0x1b020782a4f7a614d x*OzaM

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.