Benign Download

Trojan-GameThief.Win32.OnLineGames.gps

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-2569843d050b46f457190ca76f9f694bec5b10b961c95a10ba67948ef857634d7b3
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x535f–0x543f
⋯3 more rows
0x538f57696e646f7773486f6f6b45784100adWindowsHookExA..
0x539f02556e686f6f6b57696e646f7773486f.UnhookWindowsHo
0x53af6f6b4578001a0043616c6c4e65787448okEx...CallNextH
0x53bf6f6f6b457800007b0147657457696e64ookEx..{.GetWind
0x53cf6f7754687265616450726f6365737349owThreadProcessI
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.